Great Circle Associates Majordomo-Workers
(December 1999)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: More issues, some patches
From: George Lindholm <George . Lindholm @ ubc . ca>
Date: Mon, 13 Dec 1999 14:37:48 -0800
To: Brock Rozen <brozen @ torah . org>
Cc: Oliver Xymoron <oxymoron @ waste . org>, "Roger B.A. Klorese" <rogerk @ QueerNet . ORG>, Dave Wolfe <dwolfe @ risc . sps . mot . com>, majordomo-workers @ GreatCircle . COM, Jason L Tibbitts III <tibbs @ hpc . uh . edu>, grimes @ waste . org
References: <Pine.LNX.4.21.9912132132190.70-100000@rina.torah.org>

Brock Rozen wrote:
> 
> On Mon, 13 Dec 1999 at 12:11, Oliver Xymoron wrote about "Re: More issues,...":
> 
> > > I thought sendmail's expanding owner- addresses *was* the reason for the
> > > comma.
> >
> > I'm not sure what the problem you're pointing to is. Is it that people can
> > do an EXPN remotely?
> 
> I think that's exactly what's being discussed here. And I know this goes
> back to mj 1.9x and the security issue with the -outgoing aliases and not
> wanting people to see them, or whatever.
> 
> The trailing comma was supposed to help out, but it never did for me
> then.

As I remember it, the comma supresses the -outgoing alias from the
message headers making it "impossible" for someone outside to
email the list by bypassing the list alias and going straight to the
outgoing alias instead since they can't see what the alias is.

When I was setting up majordomo here that's what I did, and it worked
for
me.

   George
> 
> But given that sendmail allows people to turn off VRFY or EXPN very
> easily, this shouldn't be a Majordomo issue but an MTA/MDA issue. We
> shouldn't have to compensate for those that decide to leave it turned on
> (it's simply their choice) or for those that decide to turn it off -- let
> them decide how they want to do it. Nothing more than a comment in the
> docs should be necessary.
> 
> --
> Brock Rozen                                              brozen@torah.org
> Director of Technical Services                             (410) 602-1350
> Project Genesis                                     http://www.torah.org/

-- 
George.Lindholm@ubc.ca       ITServices, UBC
Programmer/Analyst

phone:    604.822.4375       fax:      604.822.5116


Follow-Ups:
References:
Indexed By Date Previous: Re: Mj2 sendmail aliases problem (was: More issues)
From: Brock Rozen <brozen@torah.org>
Next: Re: More issues, some patches
From: Oliver Xymoron <oxymoron@waste.org>
Indexed By Thread Previous: Re: More issues, some patches
From: Dave Wolfe <dwolfe@risc.sps.mot.com>
Next: Re: More issues, some patches
From: Oliver Xymoron <oxymoron@waste.org>

Google
 
Search Internet Search www.greatcircle.com