Re: [Mailman-Users] Is mailman vulnerable to the httpoxy bug?

2016-07-23 Thread Perry E. Metzger
proxy (which is what I did on my web servers as soon as this came out). I would agree that nuking any environment variable that you don't know that you need is probably a good idea in general. It increases safety. Perry -- Perry E. Metzgerpe...@piermont.com --

Re: [Mailman-Users] Is mailman vulnerable to the httpoxy bug?

2016-07-23 Thread Perry E. Metzger
scripts explicitly look at HTTP_PROXY, it is that many things *implicitly* look at it.) Perry -- Perry E. Metzgerpe...@piermont.com -- Mailman-Users mailing list Mailman-Users@python.org https://mail.python.org/mailman/listinfo/mai

Re: [Mailman-Users] Is mailman vulnerable to the httpoxy bug?

2016-07-22 Thread Perry E. Metzger
On Fri, 22 Jul 2016 09:48:34 -0700 Mark Sapiro <m...@msapiro.net> wrote: > On 07/22/2016 08:55 AM, Perry E. Metzger wrote: > > On Wed, 20 Jul 2016 12:02:13 -0700 Mark Sapiro > > <m...@msapiro.net> > >> > >> I am not an expert on httpoxy at all, bu

Re: [Mailman-Users] Is mailman vulnerable to the httpoxy bug?

2016-07-22 Thread Perry E. Metzger
On Tue, 19 Jul 2016 17:25:00 -0400 Jim Popovitch <jim...@gmail.com> wrote: > On Tue, Jul 19, 2016 at 5:10 PM, Perry E. Metzger > <pe...@piermont.com> wrote: > > https://httpoxy.org/ seems to impact any python program (among > > many others) that runs un

Re: [Mailman-Users] Is mailman vulnerable to the httpoxy bug?

2016-07-22 Thread Perry E. Metzger
On Wed, 20 Jul 2016 12:02:13 -0700 Mark Sapiro <m...@msapiro.net> wrote: > On 07/19/2016 02:10 PM, Perry E. Metzger wrote: > > https://httpoxy.org/ seems to impact any python program (among > > many others) that runs under cgi. Does it cause trouble for > > mailman? What

[Mailman-Users] Is mailman vulnerable to the httpoxy bug?

2016-07-19 Thread Perry E. Metzger
https://httpoxy.org/ seems to impact any python program (among many others) that runs under cgi. Does it cause trouble for mailman? What is a reasonable mitigation? Perry -- Perry E. Metzgerpe...@piermont.com -- Mailman-Users

Re: [Mailman-Users] Handling bogus subscribe requests

2016-01-17 Thread Perry E. Metzger
On Sun, 17 Jan 2016 09:34:35 -0800 Mark Sapiro <m...@msapiro.net> wrote: > On 01/17/2016 06:34 AM, Perry E. Metzger wrote: > > > > Mostly it just requires registration. Doing a custom template is > > probably fine for someone like me who is able to deal with the &

Re: [Mailman-Users] Handling bogus subscribe requests

2016-01-17 Thread Perry E. Metzger
use it yourself of course if you find it overly vile. Perry -- Perry E. Metzgerpe...@piermont.com -- Mailman-Users mailing list Mailman-Users@python.org https://mail.python.org/mailman/listinfo/mailman-users Mailman FAQ: http://wiki.

Re: [Mailman-Users] Handling bogus subscribe requests

2016-01-16 Thread Perry E. Metzger
ways of stopping them. What's a good technique at this point to slow them down besides regexps? I'm stuck on 2.1.18 at the moment as a debian user. Perry -- Perry E. Metzgerpe...@piermont.com -- Mailman-Users mailing list Mai

Re: [Mailman-Users] Handling bogus subscribe requests

2016-01-16 Thread Perry E. Metzger
On Sat, 16 Jan 2016 19:02:58 -0500 "Perry E. Metzger" <pe...@piermont.com> wrote: > On Thu, 14 Jan 2016 08:55:21 -0600 "Gibbs, David" > <da...@midrange.com> wrote: > > On 1/12/2016 11:54 AM, Mark Sapiro wrote: > > > > > There are thre

Re: [Mailman-Users] Handling bogus subscribe requests

2016-01-16 Thread Perry E. Metzger
On Sat, 16 Jan 2016 16:52:29 -0800 Mark Sapiro <m...@msapiro.net> wrote: > On 01/16/2016 04:02 PM, Perry E. Metzger wrote: > > > > I have direct evidence that the asshats are now using "+" strings > > after the main address that are not strictly num

Re: [Mailman-Users] Bogus/forged subscription attempts: request for comments and possibly data

2014-06-10 Thread Perry E. Metzger
On Tue, 10 Jun 2014 11:48:49 +0900 Stephen J. Turnbull step...@xemacs.org wrote: Perry E. Metzger writes: BTW, I don't quite understand this. Why would splatting random addresses at you help them? Why not just pick real addresses they control? Successfully subscribing is easy

Re: [Mailman-Users] Bogus/forged subscription attempts: request for comments and possibly data

2014-06-09 Thread Perry E. Metzger
option. (Mine all have ALLCAPS@ addresses.) Perry -- Perry E. Metzgerpe...@piermont.com -- Mailman-Users mailing list Mailman-Users@python.org https://mail.python.org/mailman/listinfo/mailman-users Mailman FAQ: http

Re: [Mailman-Users] Bogus/forged subscription attempts: request for comments and possibly data

2014-06-09 Thread Perry E. Metzger
random addresses at you help them? Why not just pick real addresses they control? Successfully subscribing is easy, and generating seemingly random addresses won't get them subscribed since the addresses will never get a confirmation round trip. Perry -- Perry E. Metzgerpe

[Mailman-Users] feedback when users are unsubscribed for bounces

2013-09-17 Thread Perry E. Metzger
Is there any easy way to get the x has unsubscribed messages to distinguish when people are removed due to bounces from when they leave a list of their own accord? -- Perry E. Metzgerpe...@piermont.com -- Mailman-Users mailing

Re: [Mailman-Users] tuning bounce behavior with VERP

2013-09-12 Thread Perry E. Metzger
even though the settings should be doing that. Is there a good way to examine the database of bounce information being stored so that I can tell what Mailman things the state for such users is? Perry -- Perry E. Metzgerpe...@piermont.com

[Mailman-Users] tuning bounce behavior with VERP

2013-09-02 Thread Perry E. Metzger
? Perry -- Perry E. Metzgerpe...@piermont.com -- Mailman-Users mailing list Mailman-Users@python.org http://mail.python.org/mailman/listinfo/mailman-users Mailman FAQ: http://wiki.list.org/x/AgA3 Security Policy: http://wiki.list.org/x

Re: [Mailman-Users] tuning bounce behavior with VERP

2013-09-02 Thread Perry E. Metzger
. :) Perry -- Perry E. Metzgerpe...@piermont.com -- Mailman-Users mailing list Mailman-Users@python.org http://mail.python.org/mailman/listinfo/mailman-users Mailman FAQ: http://wiki.list.org/x/AgA3 Security Policy: http

Re: [Mailman-Users] Ordering of messages in the moderation queue by date?

2013-06-18 Thread Perry E. Metzger
there, and I'm not going to think about checking in the multiple box case for conflicting checkbox options applied to the same sender. -- Perry E. Metzgerpe...@piermont.com -- Mailman-Users mailing list Mailman-Users@python.org http

[Mailman-Users] Ordering of messages in the moderation queue by date?

2013-06-16 Thread Perry E. Metzger
hard would it be to fix? -- Perry E. Metzgerpe...@piermont.com -- Mailman-Users mailing list Mailman-Users@python.org http://mail.python.org/mailman/listinfo/mailman-users Mailman FAQ: http://wiki.list.org/x/AgA3 Security Policy