We're running 2.1.4 in production.  Last week, a couple of our
lists got subscribed to a mail-archiver service, apparently by a
subscriber to those lists.  The mail archiving service doesn't do
any subscription confirmations, and the subscriptions to it were
confirmed via the web interface.

I don't quite see how this could happen.  The mail archiver and the
place where the confirmations came from are a continent and an
ocean apart, so collusion is unlikely.  Any ideas?  Is there a way
for someone submitting a subscription request to get a copy of the
confirmation email from mailman?  If so, there could be a hole to
for maliciously-generated subscriptions.

  -les
_______________________________________________
Mailman-Developers mailing list
[EMAIL PROTECTED]
http://mail.python.org/mailman/listinfo/mailman-developers
Unsubscribe: 
http://mail.python.org/mailman/options/mailman-developers/archive%40jab.org

Reply via email to