LSTOWN-L Archives

LISTSERV List Owners' Forum

LSTOWN-L

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Topic: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
"Paul E. Prusakowski" <[log in to unmask]>
Mon, 12 Mar 2001 19:13:28 -0500
text/plain (33 lines)
This is the second time in a month that we had experienced this sort of
problem.  The first time was a problem with a server in Germany that shot
out a copy of a single message every 6 minutes for an entire weekend.  For
some lucky reason, it only came to my box as list-owner and it didn't affect
the rest of the subscriber base.

This time, it happened as stated by everyone else. Old messages got sent and
viewed by the listserv software as NEW messages, and got reposted with the
March 9 date.  All traced back to problems at mail.houston.rr.com.

My concern is that this can and most likely will happen again at some point,
and possibly with a larger backlog of messages.

The problem seems to lie in the fact that another system can generate a
message that is viewed by the listserv as an original message from a
qualified subscriber.... that is what concerns me.  My list is for
subscribers only, and they have enough difficulties sending from a system
when their mail profile has been changed slightly from the email address
that they have subscribed from... but here is a case where a system that is
not even related to our listserv, other than having a few individuals from
mail.houston.rr.com subscribed, has the ability to easily post messages to
the entire list.

This is a definite security flaw that needs to be tightened up some how.

I don't know all the technical details behind the problem, but it obvious
that there is a problem that needs correction to prevent this from happening
again by mistake or intentionally.

Thanks.

Paul Prusakowski

ATOM RSS1 RSS2