|
Sender: |
Revised LISTSERV forum <LSTSRV-L@CEARN> |
Subject: |
|
From: |
"Geert K. Marien" <GKMCU@CUNYVM> |
Date: |
Fri, 22 Sep 89 10:26:45 EDT |
In-Reply-To: |
Message of Fri, 22 Sep 89 09:43:53 EDT from <GETTES@PUCC> |
Reply-To: |
Revised LISTSERV forum <LSTSRV-L@CEARN> |
On Fri, 22 Sep 89 09:43:53 EDT Michael R. Gettes said:
>On Fri, 22 Sep 89 14:00:09 GMT Eric Thomas said:
>>Fine, now any self-respecting hacker can send an AFD FOR *@* DEL * * *
>>from the postmaster userid to your server, and zzzap, all AFD's gone in a
>>matter of seconds. But then, who cares about security?
>>
>> Eric
>
>So, are you saying that it is trivial for a hacker to look like the postmaster
>to listserv without actually getting onto the postmaster account or listserv?
>If this is so, that is security whole that should certainly be fixed.
>If it is necessary for someone to actually get on to listserv or get on
>to a postmaster account to do this then I do not see this as a security
>breach.
>
>/mrg
There are well known security problems on the network that exist and
are not necessarily specific to Listserv for which some amount of
protection is available. The only secure system is one with no inside
or outside connections and no users.
/Geert
|
|
|