LSTSRV-L Archives

LISTSERV Site Administrators' Forum

LSTSRV-L

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Topic: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
lsvadmin <[log in to unmask]>
Mon, 20 Dec 1999 12:34:21 +1100
text/plain (26 lines)
I brought this up previously about the bookmark url's. The answers I
received from LSoft and from list members didnt do anything to address
my concerns, so I have spent the weekend researching and contacting
other security related lists overseas and here and the answer is pretty
much universal.

"If you are bookmarking the wrong thing, then I would consider it a major
security flaw in the product, but I have seen other interfaces that do the
same thing."

Whether you take notice of me or not is irrelevant, but these people are
widely respected in the security field. So please take notice of them. I
will provbide LSoft with a contact for the security list if required. And I
recommend that LSoft does so, then they can put it to security
professionals themselves about how concerned to be. I made no
mention of the product or company that I was questioning about, I didnt
want to cause any unwarranted backlash.

For here, I will be recommending that the Listserv web interface be used
only by administrators of Listserv until the web server it runs on is
secured enough to force a trustable validation from list owners using it.

sorry bout that folks, but you really need to look at this.

ICoS

ATOM RSS1 RSS2