Automatic download list serves as spamlist

Krzysztof Chrapka chrapka.k at gmail.com
Mon May 25 13:49:20 UTC 2009


To KDE.org team,
unfortunatly after posting some contents on kde-looks.org, I got my very first Nigerian spam letter. After quick googling out where did my e-mail address croped up in the Internet, I found it on the http://download.kde.org/khotnewstuff/amarokscripts/amarokscripts.xml automatic download list. As far as I remember, I have not allowed redistributing my email address and I was assured that it will not be visible to the other users. Moreover, I am unable to change it in a spam-bot secure method (with replacing @ or dot characters), since you are checking validity of address after each change. Although the email address was given on page associated to  opendesktop.org, it leaked out to the open Internet from the KDE project domain.

Hoping, this thoughtless security hole will be patched soon,
Yours sincerely,
Krzysztof Chrapka
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://mail.kde.org/mailman/private/kde-www/attachments/20090525/b802025e/attachment.html>


More information about the kde-www mailing list