Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

Unfortunate interaction between EZMLM and MessageLabs virus scanning
From: Ben Laurie <ben () algroup co uk>
Date: Tue, 07 May 2002 17:17:02 +0100

The widely used mailing list manager, EZMLM
(http://cr.yp.to/ezmlm.html), when sending mails for moderation, sets a
reply-to address which, if responded to, will cause the mail to be
accepted for distribution.

MessageLabs (http://www.messagelabs.com/) offer an email virus scanning
service which, unfortunately, sends virus alerts to, amongst others, the
reply-to address.

This causes email bearing viruses to be automatically accepted even when
sent to a moderated list.

MessageLabs have, in a telephone conversation earlier today,
acknowledged this problem and anticipate a fix in the near future. In
the meantime, we advise all moderators of ezmlm mailing lists to not use
MessageLabs vetted email addresses for moderation, or to temporarily
disable the list pending a fix.

Stop Press
----------

I have heard that some people within MessageLabs think that they should
argue about the RFCs rather than fix this problem, so MessageLabs
customers might care to inform them directly of their own opinions.

Cheers,

Ben.

--
http://www.apache-ssl.org/ben.html       http://www.thebunker.net/

"There is no limit to what a man can do or how far he can go if he
doesn't mind who gets the credit." - Robert Woodruff


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]