diff options
Diffstat (limited to 'informationals/teso-i0019.txt')
| -rw-r--r-- | informationals/teso-i0019.txt | 34 |
1 files changed, 34 insertions, 0 deletions
diff --git a/informationals/teso-i0019.txt b/informationals/teso-i0019.txt new file mode 100644 index 0000000..9ce06b9 --- /dev/null +++ b/informationals/teso-i0019.txt | |||
| @@ -0,0 +1,34 @@ | |||
| 1 | 0019 2000/03/21 Majordomo include inconveniences | ||
| 2 | |||
| 3 | ==== TESO Informational ======================================================= | ||
| 4 | This piece of information is to be kept confidential. | ||
| 5 | =============================================================================== | ||
| 6 | |||
| 7 | Description ..........: Majordomo include inconveniences | ||
| 8 | Date .................: 2000/03/21 19:26 | ||
| 9 | Author ...............: typo | ||
| 10 | Publicity level ......: well known | ||
| 11 | Affected .............: Mailing Lists | ||
| 12 | Type of entity .......: implementation | ||
| 13 | Type of discovery ....: useful information | ||
| 14 | Severity/Importance ..: medium | ||
| 15 | Found by .............: everyone? | ||
| 16 | |||
| 17 | Information =================================================================== | ||
| 18 | |||
| 19 | Most people that use Majordomo with the rules imposed by the resend script | ||
| 20 | use another, supposed to be secret, MTA include for the real outgoing mails | ||
| 21 | instead of a dedicated bulk mailer. | ||
| 22 | |||
| 23 | But if you know the name of the real include you can simply bypass all | ||
| 24 | rules that resend enforces. | ||
| 25 | |||
| 26 | Lets take a reallife example and look at some headers: | ||
| 27 | |||
| 28 | Received: (from majordomo@localhost) by kxxxxxxaxxe.org (8.9.3/8.9.3) | ||
| 29 | id QAA21181 for linuxde-outgoing; Tue, 21 Mar 2000 16:30:36 +0100 | ||
| 30 | |||
| 31 | the real name is linuxde-outgoing.. mails sent there can be of | ||
| 32 | arbitary size, and bypass moderation, headers, footers, banned words,... | ||
| 33 | |||
| 34 | =============================================================================== | ||
