All of lore.kernel.org
 help / color / mirror / Atom feed
* Changing mailing list subscription process
@ 2008-05-29 23:09 Robin H. Johnson
  2008-05-30 12:23 ` Chris Webb
                   ` (11 more replies)
  0 siblings, 12 replies; 13+ messages in thread
From: Robin H. Johnson @ 2008-05-29 23:09 UTC (permalink / raw)
  To: mlmmj

[-- Attachment #1: Type: text/plain, Size: 1713 bytes --]

Presently, we have been suffering some spam attacks against some of the
Gentoo mailing lists, because of spammers using auto-responders.

Here's how they are conducting the attack:

1. Spammer forges a mail from $LIST+subscibe@gentoo.org, sending it to
   an auto-responder.
2. Lists sends a confirmation mail to the auto-responder.
3. Auto-responder sends mail, with intact confirmation data back to the
   confirmation address (in Reply-To).
4. Auto-responder is now subscribed to the mailing list.
5. Spammer forges a mail from the auto-responder, to the normal mailing
   list address.

I tried adding a specific Reply-To address in the header of the list
text/ file, but it's made to part of the mail body instead of the
header.

Here's what I wanted to do, but isn't taken:
--- original/sub-confirm	2008-05-29 20:42:06.000000000 +0000
+++ spamproof/sub-confirm	2008-05-29 21:28:51.000000000 +0000
@@ -1,4 +1,5 @@
 Subject: Confirm subscription to $listaddr$
+Reply-To: DO NOT REPLY <devnull@localhost.invalid>
 
 Hi, this is the mlmmj program managing the mailinglist
 
@@ -16,8 +17,8 @@
 your address. Secondly it makes sure someone else did not try and
 subscribe your emailaddress without your permission.
 
-Your mailer may automatically reply to the confirmation address when you hit
-the reply button.
+Due to repeat spam abuse, you must copy the $confaddr$ in your mail client
+manually. Just hitting reply will not deliver to a valid location.
 
 The subject and the body of the mail can be anything.

-- 
Robin Hugh Johnson
Gentoo Linux Developer & Infra Guy
E-Mail     : robbat2@gentoo.org
GnuPG FP   : 11AC BA4F 4778 E3F6 E4ED  F38E B27B 944E 3488 4E85

[-- Attachment #2: Type: application/pgp-signature, Size: 329 bytes --]

^ permalink raw reply	[flat|nested] 13+ messages in thread

end of thread, other threads:[~2008-06-04 21:48 UTC | newest]

Thread overview: 13+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2008-05-29 23:09 Changing mailing list subscription process Robin H. Johnson
2008-05-30 12:23 ` Chris Webb
2008-05-30 14:51 ` Benny Pedersen
2008-05-30 15:08 ` Christian Laursen
2008-05-30 16:02 ` Robin H. Johnson
2008-05-30 16:04 ` Robin H. Johnson
2008-05-30 18:29 ` Thomas Goirand
2008-05-30 19:47 ` Robin H. Johnson
2008-06-02 21:33 ` Chris Webb
2008-06-02 21:55 ` Mads Martin Joergensen
2008-06-04  5:08 ` Robin H. Johnson
2008-06-04  6:58 ` Morten K. Poulsen
2008-06-04 21:48 ` Robin H. Johnson

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.