[SAC] [OSGeo] #2597: Dangerous emails leaking into grass-web mailing list: mailman blocking fails

OSGeo trac_osgeo at osgeo.org
Thu May 6 00:53:52 PDT 2021


#2597: Dangerous emails leaking into grass-web mailing list: mailman blocking
fails
---------------------------+-----------------------
 Reporter:  neteler        |      Owner:  sac@…
     Type:  task           |     Status:  new
 Priority:  critical       |  Milestone:  Unplanned
Component:  Systems Admin  |   Keywords:  mailman
---------------------------+-----------------------
 At time, dangerous emails are leaking into the moderated "grass-web"
 mailing list, see https://lists.osgeo.org/pipermail/grass-
 web/2021-May/date.html

 While I had added <noreply at microsoftteams.uservoice.com> to the mailman
 discard section ("Privacy" setting), filtering still fails as seen below.

 Question: how to get rid of this rubbish? Can we do anything at low level?

 In /var/log/mail.log there are entries like this:


 {{{
 May  2 17:44:15 osgeo6 postgrey[4517]: action=pass, reason=triplet found,
 client_name=unknown, client_address=46.183.220.114,
 sender=noreply at microsoftteams.uservoice.com, recipient=grass-
 web at lists.osgeo.org
 }}}

 Garbage email example:


 {{{
 ---------- Forwarded message ---------
 From: Email ADMIN <noreply at microsoftteams.uservoice.com>
 Date: Thu, May 6, 2021 at 3:24 AM
 Subject: [GRASS-web] lists.osgeo.org : (6)Incoming messages are blocked on
 your mail server.
 To: <grass-web at lists.osgeo.org>


 You have new held messages


 Dear grass-web at lists.osgeo.org

 Incoming messages are blocked on your mail server.
 You have {6} blocked emails on your server waiting to deliver to grass-
 web at lists.osgeo.org

 Enable data to retrieve messages

 Click Here To Enable Data


 © 2003 - 2021 WebClient Services Limited.
 _______________________________________________
 grass-web mailing list
 grass-web at lists.osgeo.org
 https://lists.osgeo.org/mailman/listinfo/grass-web
 }}}

-- 
Ticket URL: <https://trac.osgeo.org/osgeo/ticket/2597>
OSGeo <https://osgeo.org/>
OSGeo committee and general foundation issue tracker.


More information about the Sac mailing list