Re: [Mailman-Developers] Mailing lists exploited

2017-05-17 Thread Jonathan Knight
Hi Daniel Our use case is that most (but not all) of our lists are internal and so the archives are not public. However the listinfo pages are public for the few public lists that we run and to allow of campus staff and students to access the list management screens. So for us, hiding the list

Re: [Mailman-Developers] Mailing lists exploited

2017-05-17 Thread Daniel Kahn Gillmor
On Wed 2017-05-17 09:20:21 +0100, Jonathan Knight wrote: > The attack we're trying to defend against is a scripted one which grabs a > list of all the mailing lists, then harvests the administrator email and > then tries to spam each list using the administrator as a sender address. > > If the

Re: [Mailman-Developers] Mailing lists exploited

2017-05-17 Thread Jonathan Knight
The attack we're trying to defend against is a scripted one which grabs a list of all the mailing lists, then harvests the administrator email and then tries to spam each list using the administrator as a sender address. If the archives are public then I guess you could write a reasonable