[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Anonymous code name allocated. // penet hack



>On Tue, 2 Aug 1994, L. Todd Masco wrote:
>
>>  > It isn't even necessary to forge the return address, because majordomo
>>  > doesn't check.

>> In my experience, listservers will clear any commands that don't come from
>>  the person affected by passing them on for processing by the list
>>  maintainer as a security precaution.  I had assumed majordomo
>>  did this, but I'm not certain.

Tod and Robert are right, I was wrong... I just checked this by creating a
dummy account from a different address.  When I tried to unsubscribe the
dummy account from my usual account, I got a message telling me the request
had been deferred to the list owner.  So it's not *totally* trivial to mess
with the list...

Doug