Subscription bomb tracing - feature request.

From: Alan Brown (alanat_private)
Date: Mon Jan 03 2000 - 18:15:22 PST

  • Next message: k0ad k1d: "Another search.cgi vulnerability"

    There have been quite a few subscribe bombs tossed around recently.
    
    While it's nice to see that most mailing list admins use confirm
    requests now, it would be a great help if the confirm requests contained
    at least the headers of the original request, to aid victims in tracing
    their attacker(s).
    
    One attack recently notified to ORBS attempted to sign the victim up to
    26,000 different lists via insecure email relays.
    
    The confirmation requests alone constituted a fairly substantial denial
    of service attack, as did the huge number of bounces the victim got.
    
    I've only ever seen one mailing list which actually showed where the
    signup request came from. Times are still changing and adding an audit
    trail would make life easier all round.
    
    AB
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 15:25:45 PDT