procmail
[Top] [All Lists]

Re: pre-appology for unsub results message...

1999-01-06 15:34:44
"Professional" == Professional Software Engineering 
<PSE-L(_at_)mail(_dot_)professional(_dot_)org> writes:

  Professional> Mea culpa.

  Professional> I just realized that a test message I sent to the 
procmail-request was done
  Professional> with a reply-to using my procmail config -- so the unsub 
results will end
  Professional> up being directed to this list.  Oops.

  Professional> background for the test message: I'm considering making a 
simple web-based
  Professional> unsub interface for the procmail list -- a place to direct 
people to go
  Professional> when they want to unsub and can't cope with email properly.

(By the way, I am the unfortunate user who had the email bounce
problem.)

Despite the fact that it's relatively easy to forge the "From:"
address in an unsubscribe (or subscribe) request, you still have to
know what you're doing.  If you provide a web address to
subscribe/unsubscribe, and you have the ability to enter any address
you want, then it seems like this may give less-knowledgeable users
the ability to create tame "denial-of-service" attacks.

-- 
===============================================================================
David M. Karr    |   Unix/Java/C++/X/Emacs   | TCSI & Best Consulting
dkarr(_at_)tcsi(_dot_)com   |     Software Engineer     | w:(425)487-8578

<Prev in Thread] Current Thread [Next in Thread>