[Mailman-Users] Issue that Can cause mass spam for site admin

2008-07-17 Thread Robert Campbell
While testing my local install, one of my colleges found an exploit with the "forgot password" and "unsubscribe" option of the web UI and ended up spamming me ( on purpose to prove the pt), 90 emails to the list-owner in under 5 min as a different user ( mainly my test user), so this could be easil

[Mailman-Users] Apache Resource Issue

2008-07-05 Thread Robert Campbell
Ok, I had mailman working not less than 10 min ago, and now I get a 500 error. The apache error log shows the following when I try to go to admin, listinfo, and couple of the other cgi . (11)Resource temporarily unavailable: couldn't create child process: 11: listinfo (11)Resource temporarily un

Re: [Mailman-Users] Apache and pipermail 403 issues

2008-07-03 Thread Robert Campbell
Thank you Mark that worked perfectly. On Wed, Jul 2, 2008 at 7:51 PM, Mark Sapiro <[EMAIL PROTECTED]> wrote: > Robert Campbell wrote: > > >Currently when ever I try to get to the mailman archives for any of the > >mailing lists I revcive a 403 error. > >When I ch

Re: [Mailman-Users] Apache and pipermail 403 issues

2008-07-02 Thread Robert Campbell
Currently when ever I try to get to the mailman archives for any of the mailing lists I revcive a 403 error. When I check the apache error log i see the following line: [Wed Jul 02 10:28:52 2008] [error] [client ] client denied by server configuration: /archives/public/ The Private folder is owne