[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Anonymous code name allocated. // penet hack
>On Tue, 2 Aug 1994, L. Todd Masco wrote:
>
>> > It isn't even necessary to forge the return address, because majordomo
>> > doesn't check.
>> In my experience, listservers will clear any commands that don't come from
>> the person affected by passing them on for processing by the list
>> maintainer as a security precaution. I had assumed majordomo
>> did this, but I'm not certain.
Tod and Robert are right, I was wrong... I just checked this by creating a
dummy account from a different address. When I tried to unsubscribe the
dummy account from my usual account, I got a message telling me the request
had been deferred to the list owner. So it's not *totally* trivial to mess
with the list...
Doug