sudoroom / sudo-infrastructure

Tracking issues related to sudoroom's infrastructure (web servers, wiki, mailing lists, etc)
2 stars 1 forks source link

Our mailman web interface is being used to mail bomb someone #7

Open rcsheets opened 6 years ago

rcsheets commented 6 years ago

While watching mailman logs yesterday, I determined that our mailman web interface was being abused to send large numbers of subscription confirmation requests to a specific email address. As a workaround, I replaced /usr/lib/cgi-bin/mailman/subscribe, disabling direct subscription requests over the web.