>> This seems like it is about to become an accidental denial of service
GD> attack
>> on this mailing list.  Might be a good idea to find a way of preventing
GD> this
>> before people who don't like SA catch on...
>>
Pretty easy, actually.

The list manager should

1. Upgrade Mailman. (they are running a rather antiquated
version)

2. Use mailman administrative features to either prohibit
posting of email with attachments, OR to limit the size of
the email. Most of this worms are pretty large, so mail list
settings that allowed mail under 20k to go through but held
the rest for moderator approval would tend to let most email
through but prevent worms and viruses.

It is ironic that a mailing list devoted to the discussion
of software which filters email is itself vulnerable to
allowing mail with spam and/or worm attachments to get
through.  It is a very simple fix - I don't even know if my
step #1 is required, it's just that I know that
administrative screening options have improved with later
versions of Mailman.

-Abigail



-------------------------------------------------------
This SF.Net email sponsored by: Free pre-built ASP.NET sites including
Data Reports, E-commerce, Portals, and Forums are available now.
Download today and enter to win an XBOX or Visual Studio .NET.
http://aspnet.click-url.com/go/psa00100006ave/direct;at.asp_061203_01/01
_______________________________________________
Spamassassin-talk mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/spamassassin-talk

Reply via email to