As most people remotely interested in computer security should know, bugtraq is one of the ultimate mailing list one should subscribe in order to get the latest news or vulnerabilities (sans full-disclosure and a few others). But few people mentions what should be done before sending to the mailing list, and what will happen afterwards. Here is my little experience to be shared:
- Before sending email, make sure the email is properly signed with PGP or GPG or whatever. There is a mailing list maintainer watching over the list; email will be validated before they can be delivered to the mailing list. During the first time, the maintainer told me personally my email is delivered successfully.
- For me the most interesting part is the ‘aftermath’. Most likely the following things will be found in your mailbox afterwards:
- A few or no reply to your email (depends on people’s interest in the content, disputability, etc).
- Lots of “out of office” reply. So many.
- Several “This address does not exist” or “mailbox full” error from other mail servers around the world.
- And what distinguished bugtraq from most mailing lists: one or two email from Russia or East Europe or wherever, asking you to join malicious groups or exchange your ’scripts’ with $$$.