Subject: The mailing list for listmasters using Sympa
List archive
- From: "Mail administrator, Otto Makela" <address@concealed>
- To: sympa-users <address@concealed>
- Subject: [en@sympa] do_renewpasswd() misuse
- Date: Mon, 13 Nov 2023 00:05:54 +0200
Our Sympa installation is currently being misused by Russian well-known
hives of scum and villainy, to send out slow spam (in the range of 100
messages per day) to random Google/Hotmail/Yahoo etc customers by
connections to the web interface to use do_renewpasswd().
I am not quite sure what the payoff here is, but I suspect the long-term
intention is to cause reputation loss to our outgoing mail server since
quite a lot of the email addresses used cause bounces.
I would recommend others running Sympa check out if something similar
is happening to you, invoking do_renewpasswd() does not require a anything
very complicated. Should there really be a captcha before email is sent?
--
address@concealed (Mail Administrator, Otto J. Makela)
- [en@sympa] do_renewpasswd() misuse, Mail administrator, Otto Makela, 11/12/2023
Archive powered by MHonArc 2.6.19+.