[Mailman-Developers] Doubt about security

Adam McGreggor adam-mailman at amyl.org.uk
Mon Jan 5 19:20:54 CET 2009


On Mon, Jan 05, 2009 at 12:12:31PM -0600, skip at pobox.com wrote:
> Maybe all that's necessary is to install cgi-bin/create as
> cgi-bin/create.disabled by default, set its permissions to not allow
> execution and add a note to the installation docs about the consequences of
> through-the-web list creation and how to set it up.

Or perhaps those responsible for the set-up look at what's being set-up,
and take responsibility/make the choice themselves?

>From memory, and on Debian/FBSD systems at least, setting up Mailman still
requires intervention to sort out the web-interface/MTA integration --
even when packaged -- : that's good enough, imo.

-- 
``You can't be a real country unless you have a beer and an airline. It helps
  if you have some kind of a football team, or some nuclear weapons, but at
  the very least you need a beer.'' (Frank Zappa)


More information about the Mailman-Developers mailing list