Great Circle Associates Firewalls
(October 1993)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Sun sendmail vulnerability
From: Tom Fitzgerald <fitz @ wang . com>
Date: Fri, 22 Oct 93 13:17:39 EDT
To: lkn @ llnl . gov (Leland K. Neely)
Cc: Dan . Farmer @ corp . sun . com, rens @ imsi . com, firewalls @ greatcircle . com
In-reply-to: <9310221621 . AA07468 @ mycroft . GreatCircle . COM>; from "Leland K. Neely" at Oct 22, 93 9:25 am

> Flame on:
> Please refrain from disclosing bug particulars on an email list.

Oh, for....

There are lots of us out here with home-customized sendmails, who are
*really curious* whether we're running with the bug, and if so, what source
fixes to make.  Are we all vulnerable out here or not?  Even if the bug
isn't present in the stock 5.58, 5.65 or IDA sendmails, have we introduced
the bugs accidentally, ourselves, in our own changes?  How can we test
this?

Or are we all supposed to sit back ignorantly until a "suspicious" message
shows up in our mailboxes informing us that yes, we have now been broken
into and it's time to dig out the install tapes?

Your attitude will increase the chance that the majority of admins learn
about the problems long after the vandals, who may already be familiar with
it and have no problems whatsoever about sharing information between
themselves.

A little knowledge may be a dangerous thing, but total ignorance is worse.

-- 
Tom Fitzgerald    Wang Labs, Lowell MA, USA    fitz @
 wang .
 com   1-508-967-5278




References:
Indexed By Date Previous: Re: Sun sendmail vulnerability
From: "Perry E. Metzger" <pmetzger @ lehman . com>
Next: Re: Sun sendmail vulnerability
From: woods @ ncar . UCAR . EDU (Greg Woods)
Indexed By Thread Previous: Re: Sun sendmail vulnerability
From: Eric Conrad <conrad @ merl . com>
Next: Re: Sun sendmail vulnerability
From: woods @ ncar . UCAR . EDU (Greg Woods)

Google
 
Search Internet Search www.greatcircle.com