cpunks list server is a D.O.S. attacker
So the list's server accepts unauthenticated commands from any IP address and fowards them to the D.O.S. target. This 'feature' of the server doesn't have any legitimate purpose, since people who want to subscribe/unsubscribe/etc should send the commands using their email address, not an unauthenticated 'web' interface. At the very least the web interface should ban tor and have some kind of rate limiting instead of mindlessly fowarding 1000s of messages to one address.
I raised something like this separately on the mailman-users list at https://www.mail-archive.com/mailman-users@python.org/msg74304.html but did not follow up on the replies. One small upshot is that if the servers are upgraded to mailman 3, there are more options for people to address the situation by contributing feature improvements to mailman, as mailman 2.1 is end of life. (this is assuming the list comes back to life)
participants (2)
-
Karl Semich
-
punk