[Mailman-Developers] Mailing lists exploited

Mark Sapiro mark at msapiro.net
Mon May 15 18:41:30 EDT 2017


On 05/15/2017 03:19 PM, Barry Warsaw wrote:
> 
> I'm a little confused by the OP.  Is it:
> 
> 1) A message to the posting address From: LISTNAME-owner at example.com is not
> being moderated?  I would expect it to be since that address is not a member
> of the list.
> 
> 2) Emailing To: LISTNAME-owner at example.com directly which would end up
> spamming the list owners?


I don't think it's either. I think it is scraping the list owner
addresses from the LISTNAME run by joe at example.com line on the web UI
pages, s/ at /@/ and spoofing that address as the sender of a spam post
to the list.

-- 
Mark Sapiro <mark at msapiro.net>        The highway is for gamblers,
San Francisco Bay Area, California    better use your sense - B. Dylan


More information about the Mailman-Developers mailing list