Bugtraq mailing list archives

Re: Exploit for sendmail smtpd bug (ver. 8.7-8.8.2).


From: reece () taz nceye net (Bryan Reece)
Date: Sun, 17 Nov 1996 19:19:43 -0000


   From:        Alan Brown <alan () manawatu gen nz>

   How many of these exploits are thwarted by setting sendmail.cf's
   O RunAsUser=postmaster switch, making /var/spool/mail and var/spool/mqueue
   664 postmaster.mail and giving postmaster a shell of /bin/false (C
   version, compiled -Bstatic.)


Not quite as many as simply getting rid of sendmail and using
something else.  Has there ever been a security-related problem with
qmail?



Current thread: