On 07/04/2014 08:35 AM, Robert Heller wrote:
> You can join the list and turn off moderation for your self OR 
> add you E-Mail address to the list of non-members that can post to the list.


This method of posting to a 'newsletter' list is insecure. Any list
member who sees the address that posts are From: and wants to post can
just spoof that From: address in his own post. Also, random spam From:
the authorized address and To: the list will be accepted.

The secure method is to leave everyone moderated and post with an
Approved: header as discussed in the FAQs at
<http://wiki.list.org/x/3YA9> and <http://wiki.list.org/x/XIA9>.

-- 
Mark Sapiro <m...@msapiro.net>        The highway is for gamblers,
San Francisco Bay Area, California    better use your sense - B. Dylan
------------------------------------------------------
Mailman-Users mailing list Mailman-Users@python.org
https://mail.python.org/mailman/listinfo/mailman-users
Mailman FAQ: http://wiki.list.org/x/AgA3
Security Policy: http://wiki.list.org/x/QIA9
Searchable Archives: http://www.mail-archive.com/mailman-users%40python.org/
Unsubscribe: 
https://mail.python.org/mailman/options/mailman-users/archive%40jab.org

Reply via email to