[Mailman-Users] How to stop mail-bombers from abusing web subscribe page

Daniel Miller dmiller at nmap.com
Thu Jul 16 23:05:58 CEST 2015


On Thu, Jul 16, 2015 at 2:19 PM, Mark Sapiro <mark at msapiro.net> wrote:

> On 7/16/15 11:42 AM, Daniel Miller wrote:
> > Hi all,
> >
> > We have discovered "mail bomber" programs like "boom mail" abusing the
> web
> > "subscribe" feature of Mailman 2.1.15 to send hundreds of subscription
> > confirmation messages to addresses that then complain to us and report us
> > as spammers.
> ...
> > We'd love to hear if there's a better way to do this.
>
>
> Upgrade to Mailman 2.1.16 or later and enable the SUBSCRIBE_FORM_SECRET
> feature.
>

Thanks, Mark! We'll look into this option.

Dan


More information about the Mailman-Users mailing list