Great Circle Associates Firewalls
(September 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Any known security holes in the "vacation" program
From: Brad . Powell @ Eng . Sun . COM (Brad Powell)
Date: Fri, 15 Sep 1995 08:40:02 -0700
To: firewalls @ greatcircle . com, sjs @ sunthing . sjsinc . com


sjs writes:

>From firewalls-owner @
 GreatCircle .
 COM Thu Sep 14 21:49 PDT 1995
>Date: Thu, 14 Sep 1995 21:18:38 -0700
>From: sjs @
 sunthing .
 sjsinc .
 com (Stefan Jon Silverman)
>To: firewalls @
 greatcircle .
 com
>Subject: Any known security holes in the "vacation" program
>
>Folks:
>
>	I'm trying to set up an auto-responder for a couple of mail aliases
>on my mailhost. For the moment, because I don't really want to get involved
>with majordomo or any of the other mail list programs, I am using the simple
>functionality of the "/usr/ucb/vacation" program under SunOS 4.1.x. 
>
>	Given that the .forward file requires a pipe to this program, what
>are the possible security implications for this setup (i.e., are there any
>"well known" holes in this program)???


I wouldn't recommend it. vacation can write to files in the users
home directory writing an rhosts entry jumps to mind.

=======================================================================
Brad Powell : brad .
 powell @
 Sun .
 COM 
Sr. Network Security Consultant
SunNetworks, Sun Microsystems Inc. 
=======================================================================
               The views expressed are those of the author and may
                  not reflect the views of Sun Microsystems Inc.
=======================================================================

Indexed By Date Previous: Re: Firewall off Mortal Kombat XIV
From: janken @ rust . net (Kenneth J. Stephens)
Next: Re: Secure version of Sendmail
From: Rick Smith <smith @ sctc . com>
Indexed By Thread Previous: Any known security holes in the "vacation" program
From: sjs @ sunthing . sjsinc . com (Stefan Jon Silverman)
Next: Re: Any known security holes in the "vacation" program
From: yevaud @ netcom . com (Karl Wiebe)

Google
 
Search Internet Search www.greatcircle.com