LSTOWN-L Archives

LISTSERV List Owners' Forum

LSTOWN-L

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Topic: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Nathan Brindle <[log in to unmask]>
Wed, 7 Apr 1999 10:55:07 EDT
text/plain (26 lines)
If you ask me, it's a serious security problem in EUDORA.  I'm sorry but
I think this redirect feature is questionable given that it allows one
to spoof mail from somebody else.  In any case there is nothing there
for LISTSERV to check, since the actual From: address is indeed your
address.  LISTSERV doesn't check the "real name" part of the address
when it receives mail for distribution.

If you have Send= Editor or Send= Editor,Hold , you can alleviate this
problem by adding ",Confirm" at the end of the line, ie, either

* Send= Editor,Confirm

or

* Send= Editor,Hold,Confirm

As documented, this is our recommended setting for all moderated and
announce-only lists that use Send= Editor.  The setting requires that
all mails purporting to originate from the editor must be approved with
an "OK" from that editor.  This prevents people from trying to spoof
mail onto the list by forging mail from an editor address, and it also
would have stopped the message that was "bounced" back to the list (assuming
you didn't just OK it willy-nilly).

Nathan

ATOM RSS1 RSS2