Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

Re: I found this today and iam reporting it to you first!!! (fwd)
From: alan () MANAWATU GEN NZ (Alan Brown)
Date: Wed, 8 Sep 1999 08:07:28 +1200


On Sat, 4 Sep 1999, Wietse Venema wrote:

Whatever reasoning the poster used, it is invalid with any reasonable
mail system, because it is the mail system that chooses the bounce
message originator address; the bounce message originator address
is not under control by the attacker.

In other words, the suggested loop does not exist.

I can personally vouch for most cc:mail installations being so braindead
that they will bounce indefinitely. One such machine returned 5800
bounce messages from a single complaint sent to bounce messages from a single complaint sent to postmaster () rDNS about
relayed spam - with each additional message being 2kb larger than the
previous one.

Put 2 of those back-to-back and see what happens.

AB


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]