[SAC] [OSGeo] #1792: SCAM on postgis-users
OSGeo
trac_osgeo at osgeo.org
Thu Sep 15 01:20:28 PDT 2016
#1792: SCAM on postgis-users
---------------------------+--------------------
Reporter: strk | Owner: jsanz
Type: task | Status: new
Priority: normal | Milestone:
Component: Mailing Lists | Resolution:
Keywords: |
---------------------------+--------------------
Changes (by strk):
* owner: sac@… => jsanz
* component: Systems Admin => Mailing Lists
Comment:
Moving under the "Mailing Lists" component, in case the lists admin has
ideas on how to deal with this (maybe refuse mail from IP addresses not
having a valid reverse-lookup?)
Nicklas, I guess one thing you could do if you are in control of the
"jordogskog.no" domain is define a sender policy for it, specifying which
IPs would be allowed to send mail in that name (see
https://en.wikipedia.org/wiki/Sender_Policy_Framework). The rest I think
would be up to the OSGeo mail service, to refuse mail coming from non-
trusted sources...
Changing mail seems premature, the moderation bit should just give us an
idea about whether or not the attacker is going to use your email further
(for the kind of attack, it may be a one-shot).
--
Ticket URL: <https://trac.osgeo.org/osgeo/ticket/1792#comment:2>
OSGeo <http://www.osgeo.org/>
OSGeo committee and general foundation issue tracker.
More information about the Sac
mailing list