Dear friend,

David Cantrell david at cantrell.org.uk
Sun Oct 19 23:29:41 BST 2008


On Sun, Oct 19, 2008 at 08:11:12AM +0100, Jonathan Stowe wrote:
> On Sat, 2008-10-18 at 14:27 +0100, Martin A. Brooks wrote:
> > Jonathan Stowe wrote:
> > > Anyone know a good way of stopping joe-jobbed spam which doesn't involve
> > > spf and stuff ?
> > Don't have a catchall.
> That doesn't solve the particular problem here.  You lot don't see most
> of the spam that gets sent to london.pm.org because it never gets past
> the mailling list software, someone goes in an deletes it all every once
> in a while.  However in this case the spam was sent as coming from
> someone who was subscribed to the list thus goes straight through.
> Apparently this kind of thing can be caused by a potential XSS
> vulnerability in gmail so might become more common.

So we just unsub everyone using gmail. Problem solved.

-- 
David Cantrell | Minister for Arbitrary Justice

      You know you're getting old when you fancy the
      teenager's parent and ignore the teenager
        -- Paul M in uknot


More information about the london.pm mailing list