[24184] in bugtraq

home help back first fref pref prev next nref lref last post

Re: Intel.com Mailing List Arbitrary Address Removal Link

daemon@ATHENA.MIT.EDU (Thierry Zoller)
Fri Feb 8 01:23:14 2002

Message-ID: <20020206201315.18807.qmail@securityfocus.com>
Content-Transfer-Encoding: 8bit
Content-Type: text/plain; charset=iso-8859-1
Date: Wed, 6 Feb 2002 21:17:40 +0000 (GMT Standard Time)
From: Thierry Zoller <support@sniff-em.com>
To: rdnktrk@hotmail.com
Cc: bugtraq@securityfocus.com

>While Intel requires you to login to modify account information, it does not 
>require you to login to remove your e-mail (or any e-mail) from its mailing 
>list database.

This issue is valuable for plenty of mailing lists, as example take the GRC mailing list :

Exemple :
http://grc.com/mail.htm
(POST) therefor no direct link here. Enter whatever e-mail address and select "delete membership".
As for moderation, I thought specific vulnerabilities (i.e intel.com is vulnerable to etc) wouldn't be posted.

== 
Thierry Zoller
http://www.sniff-em.com

home help back first fref pref prev next nref lref last post