Skip to Content.
Sympa Menu

en - [en@sympa] do_renewpasswd() misuse

Subject: The mailing list for listmasters using Sympa

List archive

Chronological Thread  
  • From: "Mail administrator, Otto Makela" <address@concealed>
  • To: sympa-users <address@concealed>
  • Subject: [en@sympa] do_renewpasswd() misuse
  • Date: Mon, 13 Nov 2023 00:05:54 +0200

Our Sympa installation is currently being misused by Russian well-known
hives of scum and villainy, to send out slow spam (in the range of 100
messages per day) to random Google/Hotmail/Yahoo etc customers by
connections to the web interface to use do_renewpasswd().

I am not quite sure what the payoff here is, but I suspect the long-term
intention is to cause reputation loss to our outgoing mail server since
quite a lot of the email addresses used cause bounces.

I would recommend others running Sympa check out if something similar
is happening to you, invoking do_renewpasswd() does not require a anything
very complicated. Should there really be a captcha before email is sent?

--
address@concealed (Mail Administrator, Otto J. Makela)


  • [en@sympa] do_renewpasswd() misuse, Mail administrator, Otto Makela, 11/12/2023

Archive powered by MHonArc 2.6.19+.

Top of Page