[Mailman-Developers] Found a privacy loophole...

Ted Cabeen secabeen@pobox.com
Tue, 30 Nov 1999 12:08:24 -0600

In message <Pine.LNX.4.10.9911301030020.27149-100000@netserver3.otr.usm.edu>, R
ick Niess writes:
>     Whoah.  All I was pointing out was that attempting to hide the
>existence of a list to those viewing the listinfo index (by turning off
>the Advertize option) isn't entirely bulletproof.  The listinfo index page
>specifically tells them how to get to the pages for lists that they know
>exist but aren't listed there, and then it provides a link to the list
>admin overview page which lists all existing lists, hidden or not.

Are you sure that your site works that way?  If a list is unadvertised, 
then it shouldn't show up on either the listinfo or admin pages.  Are you 
really seeing all the lists on the server on the admin page?  

Ted Cabeen           http://www.pobox.com/~secabeen         secabeen@pobox.com
Check Website or finger for PGP Public Key        secabeen@midway.uchicago.edu
"I have taken all knowledge to be my province." -F. Bacon   cococabeen@aol.com
"Human kind cannot bear very much reality."-T.S.Eliot 73126.626@compuserve.com