Re: Spam vulnerability at apache

2004-04-14 Thread Adam Hardy
OK. Thanks guys! There is also the issue of getting spam directly to my email address, due to the fact that the email address is out there on the net in some list archives somewhere, vulnerable to email-address spiders looking for someone to point their spam cannons at. The careful ones, i.e.

RE: Spam vulnerability at apache

2004-04-14 Thread Mark Thomas
you prompt us otherwise it is just more spam ;) The moderators can be reached at [EMAIL PROTECTED] Mark -Original Message- From: Reshat Sabiq [mailto:[EMAIL PROTECTED] Sent: Wednesday, April 14, 2004 5:21 AM To: Tomcat Developers List Subject: Re: Spam vulnerability at apache I'm

Spam vulnerability at apache (was: Re: Photo document [TID#4977])

2004-04-13 Thread Jeff Tulley
If I am not mistaken, this email probably results from somebody on the list having one of the many recent viruses. An email is being sent from somebody's computer, with the From or Reply-to being tomcat-dev, and the To being the Russian place. The russian site has an auto-responder, and so it

Re: Spam vulnerability at apache (was: Re: Photo document [TID#4977])

2004-04-13 Thread Craig McClanahan
Jeff Tulley wrote: If I am not mistaken, this email probably results from somebody on the list having one of the many recent viruses. Actually, that is not necessary to see messages like this. All that needs to happen is that someone who is infected has both the email address of a subscriber

Re: Spam vulnerability at apache (was: Re: Photo document [TID#4977])

2004-04-13 Thread Jeff Tulley
Quite correct, though usually it IS the case that they are a subscriber, and that is why they have the address in their book. I personally am quite surprised that a group of individuals technical enough to participate in these forums would be falling prey to the viruses so often, so maybe you are

Re: Spam vulnerability at apache (was: Re: Photo document [TID#4977])

2004-04-13 Thread Adam Hardy
Actually I have found the spam resulting from this list to be negligible. That includes the user list. On 04/13/2004 06:13 PM Jeff Tulley wrote: If I am not mistaken, this email probably results from somebody on the list having one of the many recent viruses. An email is being sent from

Re: Spam vulnerability at apache

2004-04-13 Thread Craig McClanahan
Adam Hardy wrote: Actually I have found the spam resulting from this list to be negligible. That includes the user list. For that, you should thank the moderators of these two lists (Remy, Ignacio, Yoav, and Mark) who patiently field all the spam from non-subscribed addresses and filter out

Re: Spam vulnerability at apache

2004-04-13 Thread Reshat Sabiq
I'm glad to hear that this doesn't involve DNS issues. From this discussion, do i understand correctly that the following 2 addresses should be blocked? 1) [EMAIL PROTECTED] 2) [EMAIL PROTECTED] If yes, it would be nice to somehow make this stuff systematic, so that the regular lists don't have

Spam vulnerability at apache (was: Re: Photo document [TID#4977])

2004-04-12 Thread Reshat Sabiq
Hi, I extremely apologize for this message, but i think this needs to be figured out. I just yesterday registered my new email address with tomcat-dev, and i received the spam below almost immediately thereafter. Only a few people are aware of this email address, so the origin of spam info

Re: Spam vulnerability at apache

2004-04-12 Thread Reshat Sabiq
I'm sorry to report that sending the message below, caused the following to show up in my mail box. There is definitely something fishy with the apache mail servers. This does not happen when i send an email to a non-apache address. Please, let's fix this: Your Mail has been bounced from the

Re: Spam vulnerability at apache

2004-04-12 Thread Paul Speed
Everyone on the list received these e-mails since they were sent to the list. No harvesting was necessary. As I understand it, the apache mailing lists are promiscuous in a way and will easily/accidentally let any e-mail address subscribe as long as it sends a reply to a subscribe confirmation

Re: Spam vulnerability at apache

2004-04-12 Thread Paul Speed
I think this is a combination of a misconfigured mail server at one800.net and a bad e-mail address subscribed to the list. The mail server is badly configured because it replied to sender instead of the reply-to address. If it had replied to the reply-to address you would never have seen it and