[Mailman-Developers] Found a privacy loophole...

Ted Cabeen secabeen@pobox.com
Tue, 30 Nov 1999 12:08:24 -0600


In message <Pine.LNX.4.10.9911301030020.27149-100000@netserver3.otr.usm.edu>, R
ick Niess writes:
>     Whoah.  All I was pointing out was that attempting to hide the
>existence of a list to those viewing the listinfo index (by turning off
>the Advertize option) isn't entirely bulletproof.  The listinfo index page
>specifically tells them how to get to the pages for lists that they know
>exist but aren't listed there, and then it provides a link to the list
>admin overview page which lists all existing lists, hidden or not.

Are you sure that your site works that way?  If a list is unadvertised, 
then it shouldn't show up on either the listinfo or admin pages.  Are you 
really seeing all the lists on the server on the admin page?  

--
Ted Cabeen           http://www.pobox.com/~secabeen         secabeen@pobox.com
Check Website or finger for PGP Public Key        secabeen@midway.uchicago.edu
"I have taken all knowledge to be my province." -F. Bacon   cococabeen@aol.com
"Human kind cannot bear very much reality."-T.S.Eliot 73126.626@compuserve.com