[Mailman-Developers] list confirm and request addresses acting as open relay

stephen at xemacs.org stephen at xemacs.org
Thu Oct 19 03:35:37 CEST 2006


Giuliano Gavazzi writes:

 > I have then noticed that the confirm address (listname-confirm 
 > +... at ...) and the request address (listname-request at ...) act as  
 > mirrors to the alleged envelope sender, sending back the whole email  
 > after the parsed commands.

This kind of thing has been mentioned, I think, in respect of bounce
messages.

I think the real solution has to be to send only generated text when
that will do.  In case of a problem the original message should be
stored (and queued for deletion after the usual period for expiration
of a confirmation), and a reply generated containing an error message,
and the URL of the original message for diagnostic purposes.



More information about the Mailman-Developers mailing list