Great Circle Associates Majordomo-Workers
(June 1994)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: regarding CERT alert and majordomo vulnerabilities
From: Brent Chapman <brent @ mycroft . GreatCircle . COM>
Date: Fri, 10 Jun 1994 22:08:15 -0700
To: mbs @ bae . bellcore . com
Cc: Majordomo-Workers @ greatcircle . com
In-reply-to: Your message of Fri, 10 Jun 94 12:29:19 -0400

mbs@bae.bellcore.com writes:

# Regarding the CERT security advisory, I was thinking about what
# other vulnerabilities majordomo might have.
# Correct me if I'm wrong, but the following would seem to me to
# be security vulnerabilities:
# 
#    1) non-private mail lists, any user would be able to subscribe.
#    2) private mail lists, a user could masquerade as the owner of
#       the list and subscribe themselves (via telnet to sendmail port).
#    3) with the above 2 in mind,
#       thus be able to retrieve archives or digests of any list.
# 
# Would this be true?

ABSOLUTELY!

We've never claimed that Majordomo was secure against this type of
thing.

If you read the original Majordomo paper (available for anonymous FTP
from FTP.GreatCircle.COM, file pub/majordomo/majordomo.paper.ps.Z), it
talks about how the "security features" in Majordomo (password
protection on the list-owner commands) are mainly there to keep people
from making a nuisance of themselves.

There is talk of adding PGP-based authentication to version 2.0 of
Majordomo.  I'm sure this will shortly be discussed here on the
Majordomo-Workers mailing list.


-Brent
--
Brent Chapman         | Great Circle Associates  | Call or email for info about
Brent@GreatCircle.COM | 1057 West Dana Street    | upcoming Internet Security 
+1 415 962 0841       | Mountain View, CA  94041 | Firewalls Tutorial dates

Indexed By Date Previous: Re: regarding CERT alert and majordomo vulnerabilities
From: pdc@lunch.asd.sgi.com (Paul Close)
Next: Listname Aliases
From: "Roger B.A. Klorese" <rogerk@unpc.queernet.org>
Indexed By Thread Previous: Re: regarding CERT alert and majordomo vulnerabilities
From: pdc@lunch.asd.sgi.com (Paul Close)
Next: Listname Aliases
From: "Roger B.A. Klorese" <rogerk@unpc.queernet.org>

Google
 
Search Internet Search www.greatcircle.com