[Mailman-Users] virtual domain list disclosure and list email link issue

Dennison Williams dennison.williams at gmail.com
Fri Apr 16 08:08:38 CEST 2010


Hello all!,

I spent most of the day wrestling mailman and postfix into a multi site
installation and now I have it working, except there are a few issues I
am still trying to work out.

The first is that  even though I have "VIRTUAL_HOST_OVERVIEW = Yes" in
my Mailman/mm_cfg.py file I am still able to disclose other lists on
other domains through the url:
http://<virtual_domain>/mailman/listinfo/<list_name_not_in_virtual_domain>. 
There must be a another way around this, if not it should be considered
a minor security flaw.  Can anyone point me in the right direction for
preventing this?

The second issue is that all emails from the list are coming with links
from the wrong domain.  How can I get these links to reflect the domain
that the lists are for?

Thanks in advance.
-Dennis


More information about the Mailman-Users mailing list