[Mailman-Users] Virus Just Got Through on TOTALLY MODERATED list.

Dan Mahoney, System Admin danm at prime.gushi.org
Sat Jan 29 02:31:19 CET 2005


Guys,

I just had a small problem.  A virus was just sent to all the list members 
which had spoofed the moderator's email address.  No "requires approval" 
message was sent, despite the fact that everyone (even the moderator) has 
the "mod" bit set to "on".

http://securityresponse.symantec.com/avcenter/venc/data/w32.beagle.ba@mm.html

Are there any known and open bugs in 2.1.5 that would allow this behavior?

Is there any way of telling in the headers (or archives, or logs?) how a 
message was approved?

Here's the headers:

Return-Path: <vgc-announce-bounces+varoots=gushi.org at vagrassroots.org>
Received: from prime.gushi.org (localhost [IPv6:::1])
     by prime.gushi.org (8.13.1/8.13.1) with ESMTP id j0S2GH5b080701
     for <varoots at gushi.org>; Thu, 27 Jan 2005 22:50:56 -0500 (EST)
Received: from ROBERTA.net (pcp08579508pcs.alxndr01.va.comcast.net
     [68.83.208.54])
     by prime.gushi.org (8.13.1/8.13.1) with SMTP id j0S2FV8o080233
     for <vgc-announce at vagrassroots.org>;
     Thu, 27 Jan 2005 21:15:35 -0500 (EST)
Date: Thu, 27 Jan 2005 21:05:09 -0500

Any ideas?

-Dan Mahoney

--

"Ca. Tas. Tro. Phy."

-John Smedley, March 28th 1998, 3AM

--------Dan Mahoney--------
Techie,  Sysadmin,  WebGeek
Gushi on efnet/undernet IRC
ICQ: 13735144   AIM: LarpGM
Site:  http://www.gushi.org
---------------------------




More information about the Mailman-Users mailing list