Issue 18173 - zip files should not be allowed on the lists
Summary: zip files should not be allowed on the lists
Alias: None
Product: Infrastructure
Classification: Infrastructure
Component: Mailing lists (show other issues)
Version: current
Hardware: Other Linux, all
: P3 Trivial with 4 votes (vote)
Target Milestone: ---
Assignee: Unknown
QA Contact: issues@www
Keywords: oooqa
Depends on:
Reported: 2003-08-13 00:41 UTC by con.hennessy
Modified: 2008-05-17 23:52 UTC (History)
3 users (show)

See Also:
Issue Type: DEFECT
Latest Confirmation in: ---
Developer Difficulty: ---

mim ban list (2.32 KB, application/vnd.txt)
2004-03-11 07:04 UTC, lsuarezpotts
no flags Details

Note You need to log in before you can comment on or make changes to this issue.
Description con.hennessy 2003-08-13 00:41:15 UTC
a 2 MB file got dropped on the users list today, resulting in many  
understandably upset users of 56k lines. 
Please do not let zip files thru.
Comment 1 jimk55 2003-08-13 03:01:08 UTC
I have noticed although many attachments are supposed to be stripped 
I still seem to get them... 
Only to instantly delete them.  
I keep hearing that the server strips attachments but it seems to do 
so in a very ramdom manner. 
Jim TE 
Comment 2 tamblyne 2003-08-13 05:30:27 UTC
What was previously a minor irritant today became a major issue with
the monstrous attachment referenced.  Since we can't vote on this, I'd
only like to add that I'd like to see all attachments, not just zip
files, consistently stripped from the list.  

Thanks for all the good work.  


Comment 3 lsuarezpotts 2003-08-13 07:02:05 UTC
support, in PCN 12343, we specify that zip MIME types are not to be allowed on (see, for the list of lists, I believe, PCN 1171).  Yet, the 2 meg 
file got through.  Is it a new type of zip? or was it just a glitch?
Comment 4 lsuarezpotts 2003-08-13 07:26:40 UTC
CPH, can you provide the URL from the archives for the message in question? We 
might also be able to eliminate all attachments from this particular list, as it is by far 
the most popular.
(added self).
Comment 6 con.hennessy 2003-08-13 19:24:33 UTC
Tamblyne thanks for the link 
Comment 7 tamblyne 2003-08-14 13:43:50 UTC
Just happened to be in the right place at the right time -- glad I
could help.  : )

Comment 8 Unknown 2003-09-02 19:46:36 UTC
Update: Logged internal issue 22004 with CollabNet Engineering.
Action Plan: Awaiting their response.
Next Update: By end of day Thursday.
Comment 9 Unknown 2003-09-04 22:20:03 UTC
Requested an update from Engineering. 
Comment 10 con.hennessy 2003-10-09 16:30:09 UTC
Still waiting for info!
How hard can it be just to tell us what attachments are allowed on the
list ?
Another attachment (a bmp file) got thru today on the users list!

Also I think that the filters should be configured to only allow
certain attachments instead of what I think is the current policy of a
list of attachments which are *not* allowed.
Comment 11 con.hennessy 2003-10-14 21:41:08 UTC
Still no info.  
Is anyone looking at this ? 
Comment 12 Unknown 2003-10-14 22:03:10 UTC
I still have no update on the internal issue. The issue is high on my
priority list and I will update this issue when I have an update from
the engineers.
Comment 13 Unknown 2003-11-13 16:32:36 UTC
zip files are currently allowed on the mailing lists. if they are to
be disallowed Stefan and Louis should be alerted to make sure that
change is noted in the planned upgrade. 
Comment 14 con.hennessy 2003-11-17 17:17:22 UTC
Hi Kenneth, 
	Can you please indicate whether the list of file types for the mailing list is : 
exclude these file extensions; or 
allow only these file extensions. 
And please give us a complete list of the file extensions involved. 
This is because over the last few months there were several MB file attachments 
which came thru to the list. 
Also is it possible to reject mails over a specific size ? 
If there is a better forum to ask questions like this, then please tell me. 
Comment 15 Unknown 2004-02-03 22:50:28 UTC
this issue is still in the queue of the inst. engineers. I will update this
issue when they've commented internally on their progress of restricting the
incoming zips
Comment 16 Unknown 2004-02-18 05:19:33 UTC
Update :
The issue is being researched on

Next update:
Will update the reponse of the engineers as & when they occur

Comment 17 Unknown 2004-03-11 05:19:41 UTC
Update : 
Still on Engineers Queue : Will Update their Response As & When recevied

Comment 18 lsuarezpotts 2004-03-11 07:04:41 UTC
Created attachment 13709 [details]
mim ban list
Comment 19 con.hennessy 2004-03-12 16:26:54 UTC
Please change the system so that you have a "these are the only attachment 
types allowed" otherwise we will be back here every month or two (if lucky)  
to add more mime types.  
Please don't forget to also add bmps, and sxw files as a 1 MB file got onto the 
list today !!! 
Comment 20 grsingleton 2004-03-12 17:06:03 UTC
I recommend ALL attachments be stripped including html sections. By refusing
html emails as well we protect the majority from being compromised at the
expense of the few who send html emails.
Comment 21 lsuarezpotts 2004-03-12 19:19:28 UTC
CH, Ger,
thanks for feedback.  We can see about adding the other mime types. here is how it is working now. We 
have that master list that I attached. It is attached *per list*.  So, we don't want to add types that are not 
going to be true for all the other lists which limit attachments. 

Ger, we had at one point debated the idea of banning all attachments from some lists. But it was 
ultimately decided by the project leads to allow some attachmetns for the attachment-ban lists.  It's 
easier now just to add to the list.

Support will only convey a list that Sun, the client okays.  So, we can ask MH an ST to vet the 
Comment 22 grsingleton 2004-03-12 20:34:09 UTC
Thanks for the update. If the powers that be elect to use Mimedefang with qmail,
I vounteer to help. Nice thing about MD it will do all that we want it to do and
also strip out the html. Only question is, is there enough horse power to use it?
Comment 23 stx123 2004-03-19 17:32:15 UTC
Has application/zip been added to the list of to be stripped attachments?
Comment 24 grsingleton 2004-03-19 18:21:13 UTC
Steve, Can you please add all the following too:

application/vnd.sun.xml.writer sxw
application/vnd.sun.xml.writer.template stw
application/ sxg
application/vnd.stardivision.writer sdw vor
application/vnd.stardivision.writer-global sgl
application/vnd.sun.xml.calc sxc
application/vnd.sun.xml.calc.template stc
application/vnd.stardivision.calc sdc
application/vnd.sun.xml.impress sxi
application/vnd.sun.xml.impress.template sti
application/vnd.stardivision.impress sdd sdp
application/vnd.sun.xml.draw sxd
application/vnd.sun.xml.draw.template std
application/vnd.stardivision.draw sda
application/vnd.sun.xml.math sxm
application/vnd.stardivision.math smf

Note that the extention are added to my list as compared to the attachment as I
find that sometime the sun.xml.??.?? heading are ignored while action takes
place on the extention. Your call as this list is what I use at home to control
my world. 
Comment 25 Unknown 2004-03-31 13:36:06 UTC
Louis finalized the mimeremove list and mimeremove file is update as neccessary 
by the engineers.


Comment 26 Unknown 2007-02-20 05:58:24 UTC
Can we close this issue , trying to clear the Resolved Queue in preparation for
the Snake-S upgrade .
Comment 27 ace_dent 2008-05-17 21:48:07 UTC
The Issue you raised has been marked as 'Resolved' and not updated within the
last 1 year+. I am therefore setting this issue to 'Verified' as the first step
towards Closing it. If you feel this is incorrect, please re-open the issue and
add any comments.

Many thanks,
Cleaning-up and Closing old Issues
~ The Grand Bug Squash, pre v3 ~
Comment 28 ace_dent 2008-05-17 23:52:09 UTC
As per previous posting: Verified -> Closed.
A Closed Issue is a Happy Issue (TM).