Security Incidents mailing list archives

Re: CIAC Bulletin K-020


From: don () MAINFRAME DGRC CRC CA (Donald McLachlan)
Date: Mon, 6 Mar 2000 09:30:17 -0500


Is there a new vector of attack here?  I run a closed mailing list.
Since subscribing a particular (and suspicious looking remote) address
has sent 2 messages to the list.  Both got logged like:

        Mar 04 09:51:36 **************** majordomo[14644]
        {***** *** <**************@yahoo.com>}
        ABORT HOSTILE ADDRESS (path exists to /file) /

Looks awfully suspicious to me.  Only problem I know with majordomo
if is the CIAC K-020 bulletin but that is a local address raise priority
attack.

Don


Current thread: