Re: Administrivia Messages
Mark Sapiro <mark <at> msapiro.net>
2011-02-01 23:45:50 GMT
Beau Barnhart wrote:
>
>We have been asked by mail-abuse.org to make changes to the configuration
>to one of our servers. The following this their request...
Actually, the request understates the problem. See below.
>-- message from mail-abuse.org ----------
>
>Currently, when messages arrive at your mail server it runs them through
>SpamAssassin, which checks for spam and tags them. Your mail server then
>passes this tagged message to mailman.
>
>Because it is to a -request address, mailman "knows" that these messages
>should contain commands. It ignores the fact that SpamAssassin has
>already tagged it (Subject: {Definitely Spam?}), and looks through every
>line looking for a "subscribe", "unsubscribe" or other command.
>
>Of course, it doesn't find one. So, it builds up a helpful reply, sets
>the X-Administrivia header to yes, and appends the original message, and
>forwards this to the From: address.
>
>Except that the From: address is forged, so the message, and its spam
>payload, get sent to an innocent third party.
And, this would occur even if spamassassin/MailScanner/whatever didn't
tag the subject. In fact, if the message is truly spam with a forged
From:, the likelyhood that the subject contained a valid command
before tagging is small. And even if it did contain a valid command,
there is normally some reply from Mailman to the (forged) sender in
(Continue reading)