[Mailman-Users] List Security

J C Lawrence claw at kanga.nu
Wed Oct 23 18:31:41 CEST 2002


On Wed, 23 Oct 2002 08:45:46 +0200 
Dan Richter <daniel.richter at wimba.com> wrote:

> I was using Majordomo, but I got scared off when I realized that
> anyone could bypass the list posting restrictions by posting to the
> correct alias. (The normal list alias processes, then redirects to a
> second alias which blindly transmits.) The "blind forward" alias shows
> up in the headers, so I can't even hide it from people. Please
> reassure me that Mailman does not have this vulnerability!

Mailman doesn't use secret aliased.

Mailman v2.0 authenticates on From: or envelope (you pick).

Mailman v2.1 authenticates on From: and envelope.

-- 
J C Lawrence                
---------(*)                Satan, oscillate my metallic sonatas. 
claw at kanga.nu               He lived as a devil, eh?		  
http://www.kanga.nu/~claw/  Evil is a name of a foeman, as I live.





More information about the Mailman-Users mailing list