Bugtraq mailing list archives
Old sendmail bugs
From: mcn () c3serve c3 lanl gov (Michael Neuman)
Date: Thu, 29 Sep 1994 13:40:30 -0600
Subject: Old sendmail bugs I was playing with the old sendmail bug of: rcpt to: /file/name mail from: bob data <garbage> . rcpt to: /file/name mail from: bob data <data you want put into file> . I haven't actually seen this one work, so I'm not sure how the error messages look, but I did notice every Berkeley sendmail around 5.[56].x acts strangely: it will actually accept the second rcpt to: and accept whatever data you want to throw at it, but then seems to do nothing with it. Is the bug still there, and I'm just missing how to exploit it, or is it "supposed" to look like you broke sendmail? Is there any way to tell (without running a script with the above and logging into the machine I'm testing) to tell if the machine is vulnerable? Thanks! -Mike
Current thread:
- Re: Security Info (root broken), (continued)
- Re: Security Info (root broken) Valdis.Kletnieks () vt edu (Apr 18)
- Re: Security Info (root broken) Perry E. Metzger (Sep 28)
- Re: Security Info (root broken) pluvius (Sep 28)
- Re: Security Info (root broken) Charles R. Hoynowski (Sep 29)
- Re: Security Info (root broken) Christopher Klaus (Sep 28)
- Re: Security Info (root broken) Pug (Sep 29)
- Re: Security Info (root broken) John Ladwig (Sep 29)
- Re: Security Info (root broken) Pug (Sep 29)
- Re: Security Info (root broken) Casper Dik (Sep 29)
- Re: Security Info (root broken) Timothy Newsham (Sep 29)
- Old sendmail bugs Michael Neuman (Sep 29)
- Re: Security Info (root broken) Karl Strickland (Sep 29)
- Re: Security Info (root broken) Christopher Klaus (Sep 29)
- Re: Security Info (root broken) Pug (Sep 29)
- Re: Security Info (root broken) Pug (Sep 29)
- Re: Security Info (root broken) Neil Woods (Sep 29)
- IBM AIX rlogin fix jim () Tadpole COM (Sep 28)
- security problem w/ smail james w abendschan (Sep 27)
