[Mailman-Users] Loop with spoof

Simon L. Jackson simon.jackson at corpita.net
Tue Aug 19 10:07:39 CEST 2003

Dear Mailmaners,

I recently found a loop when (I think) someone sent an email with a spoofed 
from/reply-to address.

This appeared to be achieved by sending email to somelist at somedomain from 
somelist-bounces at somedomain.

We are using Postfix, and have the following Mailman aliases and virtual 
addresses set up:

somelist-bounces: "|/usr/local/mailman/mail/mailman bounces somelist"

somelist-bounces at somedomain somelist-bounces

In the end I turned off 'Send mail to poster when their posting is held for 
approval' and deleted the offending files from the 
/usr/local/mailman/qfiles/out directory.

My questions are:

1. Is this loop an error in my configuration or a bug or oversight in mailman?

2. Is there a way of getting a list of messages in transit and if necessary 
deleting them. This mail had not yet arrived at the pending requests stage.


Simon L. Jackson
Corpita Pty Ltd
Level 1
112 Sackville St
Collingwood VIC 3066
phone: +61 3 9411 4470
direct: +61 3 9411 4419
fax: +61 3 9411 4499
email: simon.jackson at corpita.net

