Opened 5 years ago

Closed 2 years ago

#2463 closed task (fixed)

geoserver-security under sustained access request attack

Reported by: jive Owned by: jsanz
Priority: normal Milestone: Unplanned
Component: SysAdmin/Mailman Keywords:


In the past couple of days we are getting emails sent to of dummy accounts trying to subscribe.

Is there any way to turn off subscription requests, and manually manage the limited list of members?

Change History (13)

comment:1 by jive, 5 years ago

Anything we can do here? Can we take this list private ...

comment:2 by strk, 5 years ago

The mailing list owner, I think, can do that from the admin panel

comment:3 by wildintellect, 5 years ago

Component: Systems AdminMailing Lists
Owner: changed from sac@… to jsanz

comment:4 by jsanz, 5 years ago

Options for admins are available at

You can remove the list from being advertised in the mailman lists frontpage, and maybe you can also add the confirm step, but as far as I know there isn't a way to fully remove the subscription procedure and move mailman to an "invitation-only" workflow.

Please let me know if you want me to change those settings for you.

comment:5 by strk, 5 years ago

I found an old thread saying this is NOT possible with Mailman (to confirm what jsanz is saying):

As this was 10 years ago I wonder if things changed...

Anyway, it's a python software, maybe we can implement that change. Pythonists reading this ?

comment:6 by strk, 5 years ago

Another option seems to be tweaking the subscription template:

comment:7 by jsanz, 5 years ago

Also, worth noting that you can add regular expressions to the ban list to entirely remove email domains.

by jive, 5 years ago

Attachment: many.png added


comment:8 by jive, 5 years ago

Please see attachment, we are getting hundreds of these subscription requests a week.

Is this mailing list just unlucky, or are others also under sustained attack.

comment:9 by jive, 5 years ago

From Jukka:

Filtering the incoming mails coming from geoserver-security list mainly hides the issue that we have with the subscription spam. Could it be possible to add recaptcha or anything to stop at least most subscription requests from a robot that some friendly people has obviously hired? The list seems to be handled by mailman and I found some links that feel relevant, like

comment:10 by neteler, 5 years ago

FYI, this mess also affects other lists: stolen email addresses seem to be registered and their respective owners complain about unsolicited subscription to the list managers (incl. me).

comment:11 by robe, 3 years ago

Is this still an issue? I know we've made several upgrades but we haven't put in recaptcha.

comment:12 by cvvergara, 2 years ago

Resolution: fixed
Status: newclosed

Was told by @jive that it can be closed

Note: See TracTickets for help on using tickets.