5 Jan
2022
5 Jan
'22
1:48 p.m.
On Tue, Jan 4, 2022 at 7:27 PM Jeremy Stanley <fungi@yuggoth.org> wrote:
On 2022-01-04 12:00:53 -0500 (-0500), Jason Poulin wrote:
Can someone take me off this list. I don’t know why I’m on it. Please. [...]
I've unsubscribed this user; it appears an attacker managed to brute-force a mailman confirmation key for a subscription request. This hole should hopefully be plugged once we migrate to Mailman v3, which employs stronger hashes for subscription confirmations.
thanks fungi for looking into that and removing that person but does it mean we potentially have more folks being spammed by us on a regular basis :/ is there a way to know all the addresses that were subscribed in this way and remove them all? regards, marios
-- Jeremy Stanley