LSTOWN-L Archives

LISTSERV List Owners' Forum

LSTOWN-L

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Topic: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Ben Parker <[log in to unmask]>
Sat, 28 Mar 1998 15:39:24 -0700
text/plain (37 lines)
On Sat, 28 Mar 1998 19:11:58 +0100, Mehmet Tutuncu <[log in to unmask]> wrote:

>We have a newsletter list, where only editors are allowed to post. last
>Friday it happened that one post that was posted by editor was distributed
>again and again (27 times) at the end we locked (hold) the list, and take
>security measures, e.g. confirming and authenticating that it is posted
>really by the editor.
>
>We suspect that some ill-willed persons were trying, to destroy the list.
>The same message is now also sended again and again, but because it is now
>not authenticated it is forwarded to editors.
>I quote relevant header of the posting under this message: Adress of the
>editor is [log in to unmask]
>Message is posted from some oar.net or tiffinu.edu pop3 server , which has
>nothing to do with editors. Any idea what we can do, to prevent this.
>
>WE have written the webmasters of tiffinu.edu and oar.net but no reply and
>our mailboxes gets fuller and fuller with unnecessary same message. Have
>any other persons experience abou this. Is this an accident, a loop or
>terrorism?

It's a mail loop.  We've had this problem before.  There are a couple of
sites in .nl (Nederlands) that have a badly broken mail server.  It mangles
the headers greatly.  It then sends the error back to the List Address and
since it appears to come From: the approved editor address, it gets posted
to the list again.  You must do 2 things.

1.  Search the headers to try to find who the mail is really for. i.e. you
are searching for the actual subscriber to your list.  Once found you set
them to NOMAIL (if you are kind) or you DELete them (if you are not).

2.  As documented, L-Soft strongly recommends you use the ,Confirm modifier
for all Send=Editor situations.  Send= Editor,Confirm or Send=
Editor,Hold,Confirm.  This is a little more work for the editor who must
approve and then separately confirm all posts.   But it prevents these kind
of mail-loops and it also is unforgable so it is more secure.

ATOM RSS1 RSS2