[Mailman-Users] Re: Subscription Attacks

2025-07-14 Thread Mark Sapiro
On 7/14/25 7:16 AM, Ralf Hildebrandt via Mailman-Users wrote: * Mark Sapiro : SUBSCRIBE_FORM_MIN_TIME = seconds(number) What's a good value? 5? It's difficult to say. I've thought 5 was good, but I've seen a recent attack where a bot would GET the form and wait 15 seconds before posting.

[Mailman-Users] Re: Subscription Attacks

2025-06-28 Thread David Andrews via Mailman-Users
At 12:38 PM 6/28/2025, Mark Sapiro wrote: On 6/28/25 09:46, David Andrews via Mailman-Users wrote: There is stuff about the "secret form?" would this work? If I understand it, the IP must match. Then there is stuff about the life of the form? Do both conditions have to be true.? Many of o

[Mailman-Users] Re: Subscription Attacks

2025-06-28 Thread Mark Sapiro
On 6/28/25 09:46, David Andrews via Mailman-Users wrote: There is stuff about the "secret form?" would this work?  If I understand it, the IP must match. Then there is stuff about the life of the form?  Do both conditions have to be true.? Many of our users do not return a form quickly, they