[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Someone's screwing around with anon.penet.fi



At 11:51 AM 4/6/96 -0800, Steve Reid <[email protected]> wrote:
>Here's another one of them unsolicited messages from anon.penet.fi.
>I have a feeling lots of people on the Cypherpunks list are going to be 
>getting these... My first post to the list was only about two days ago, 
>and someone's already messing around. :(

Anon.penet.fi is working just fine.  The problem is that someone
subscribed to the cypherpunks list as [email protected], so
any time you post to cypherpunks, anon.penet.fi receives a message
        From: [email protected]
        To: [email protected]
        Subject: My exciting post to cypherpunks
It then checks its userlist for [email protected], doesn't find you,
allocates [email protected], notifies you, and sends out the message
        From: [email protected]
        To: [email protected]
        Subject: My exciting post to cypherpunks

In my case, if I post to cypherpunks, it checks its userlist for
[email protected], finds [email protected], sees that my
password is PASSWORD, sees that the posting doesn't include the password,
and sends me a reject message.  

The problem is that, the next time you post to cypherpunks, it'll leak
your identity in the message headers; I forget the details.

The way to prevent this whole mess is to educate majordomo to turn
subscription requests from [email protected] into [email protected],
or at least to block subscription requests form [email protected].