[Mailman-Users] Re: Subscription Attacks

2025-07-14 Thread Mark Sapiro
On 7/14/25 7:16 AM, Ralf Hildebrandt via Mailman-Users wrote: * Mark Sapiro : SUBSCRIBE_FORM_MIN_TIME = seconds(number) What's a good value? 5? It's difficult to say. I've thought 5 was good, but I've seen a recent attack where a bot would GET the form and wait 15 seconds before posting.

[Mailman-Users] Re: [ext] Re: Subscription Attacks

2025-07-14 Thread Ralf Hildebrandt via Mailman-Users
* Mark Sapiro : > SUBSCRIBE_FORM_MIN_TIME = seconds(number) > > where is number is a number of seconds. You misunderstand this. It doesn't > say the form has to be submitted within that time. It says the form can't be > submitted within that time. I.e., you have to wait at least that long before