Re: [Mailman-Developers] Mailing lists exploited

May 20, 2017
4:45 p.m.
Jonathan Knight writes:
I agree with Barry. More precisely, I think we should more or less hard-code the $LIST-owner address in the mail-to URL, allow the display name (presented in the HTML) to be specified (defaulting to "$LIST-owner", maybe), and document that the list-owner address should NOT be given any special permissions (specifically, should not be subscribed to the list), and that a subscribed address should NOT be mentioned in that text. I believe the $LIST-owner address is handled by Mailman, so we can require that be configured when setting up the list.
This setup is just a BCP anyway in the "modern" Internet.
Steve
2860
Age (days ago)
2860
Last active (days ago)
0 comments
1 participants
participants (1)
-
Stephen J. Turnbull