Patch seems ok on 2.1. Is there a way to test if it's working and we are
protected? Maybe someone can respond offlist with a test URL of some kind that
would trigger a log in the mischief log.


Thanks.



On Feb 10, 2005, at 8:17 AM, [EMAIL PROTECTED] wrote:

Am I correct in assuming the attack only allows hackers to access (read)
files?  Yes, I understand that if they can read/get mailman passwords, they
can obviously change lists but nothing more nefarious than that?

they can not only get the passwords, but your subscriber lists. that is, I think, nefarious enough. it means you're one spambot away from handing over all your users to the blackhats.





------------------------------------------------------
Mailman-Users mailing list
[email protected]
http://mail.python.org/mailman/listinfo/mailman-users
Mailman FAQ: http://www.python.org/cgi-bin/faqw-mm.py
Searchable Archives: http://www.mail-archive.com/mailman-users%40python.org/
Unsubscribe: 
http://mail.python.org/mailman/options/mailman-users/archive%40jab.org

Reply via email to