Re: [Mailman-Users] Distributed mass subscribe attack?

2017-08-18 Thread Grant Taylor via Mailman-Users
On 08/18/2017 11:07 AM, Phil Stracchino wrote: I second this. It is a legitimate part of compliant email addresses, no matter how many web stores seem to believe otherwise (or are merely unaware of it). I third this. I love user+detail but HATE that poorly designed web forms balk at +, and

Re: [Mailman-Users] Distributed mass subscribe attack?

2017-08-18 Thread Phil Stracchino
On 08/18/17 12:25, tlhackque via Mailman-Users wrote: > On 17-Aug-17 16:47, Andy Cravens wrote: >> >> >> David, >> >> I forgot to mention I’m also working on a modsecurity rule to look at all >> POSTs >> and reject if they contain an email address with a + sign. >> > I understand the drive to

Re: [Mailman-Users] Distributed mass subscribe attack?

2017-08-18 Thread tlhackque via Mailman-Users
On 17-Aug-17 16:47, Andy Cravens wrote: > > > David, > > I forgot to mention I’m also working on a modsecurity rule to look at all > POSTs > and reject if they contain an email address with a + sign. > I understand the drive to suppress an attack. However, + is valid in e-mail addresses. It's

Re: [Mailman-Users] Distributed mass subscribe attack?

2017-08-18 Thread David Gibbs
On 8/17/17 3:47 PM, Andy Cravens wrote: I forgot to mention I’m also working on a modsecurity rule to look at all POSTs and reject if they contain an email address with a + sign. I'm interested in both your recaptcha mod & mod_security rule ... please post (or contact me privately) when you