[SAC] [OSGeo] #1792: SCAM on postgis-users

OSGeo trac_osgeo at osgeo.org
Thu Sep 15 01:20:28 PDT 2016


#1792: SCAM on postgis-users
---------------------------+--------------------
 Reporter:  strk           |       Owner:  jsanz
     Type:  task           |      Status:  new
 Priority:  normal         |   Milestone:
Component:  Mailing Lists  |  Resolution:
 Keywords:                 |
---------------------------+--------------------
Changes (by strk):

 * owner:  sac@… => jsanz
 * component:  Systems Admin => Mailing Lists


Comment:

 Moving under the "Mailing Lists" component, in case the lists admin has
 ideas on how to deal with this (maybe refuse mail from IP addresses not
 having a valid reverse-lookup?)

 Nicklas, I guess one thing you could do if you are in control of the
 "jordogskog.no" domain is define a sender policy for it, specifying which
 IPs would be allowed to send mail in that name (see
 https://en.wikipedia.org/wiki/Sender_Policy_Framework). The rest I think
 would be up to the OSGeo mail service, to refuse mail coming from non-
 trusted sources...

 Changing mail seems premature, the moderation bit should just give us an
 idea about whether or not the attacker is going to use your email further
 (for the kind of attack, it may be a one-shot).

--
Ticket URL: <https://trac.osgeo.org/osgeo/ticket/1792#comment:2>
OSGeo <http://www.osgeo.org/>
OSGeo committee and general foundation issue tracker.


More information about the Sac mailing list