[4148] in WWW Security List Archive
Re: E-mail
daemon@ATHENA.MIT.EDU (Joseph Iacovelli)
Tue Jan 28 09:49:45 1997
From: "Joseph Iacovelli" <joseph_iacovelli@smb.com>
Date: Tue, 28 Jan 1997 07:38:16 -0500
In-Reply-To: Kevin Gannon <kgannon@esiotrot.kst.dit.ie>
"Re: E-mail" (Jan 25, 10:13am)
To: xande <xande@venus.rdc.puc-rio.br>
Cc: www-security@ns2.rutgers.edu
Errors-To: owner-www-security@ns2.rutgers.edu
On Jan 25, 10:13am, Kevin Gannon wrote:
> Subject: Re: E-mail
> On Fri, 24 Jan 1997, Evil Pete wrote:
>
> > >I'd like to know if this program exists...
> > >It's a program that u send an e-mail to someone...then.. it bring me back
> > >the passwd file... I'd like to know this...
> > >By xande
> >
> > it is bullshit unless the email contain a executable and you are dumb
enough
> > to run it....
> >
>
> It is not bullshit if you are talking about UNIX boxes on older
> version of Sendmail it was possible to get the passwd file mailed
> out.
>
> Kev.
Kevin is right. Check out some of the known SENDMAIL books out on the
street. They talk about of the known problems of the older versions of
sendmail and how to correct them. Also, might want to take a look
at anything posted from CERT.
Joseph
--
+---------------------------+-------------------------------------------+
|Joseph Iacovelli | Phone: (212) 723-5921 |
|UNIX Systems Engineer | Beeper: (917) 812-7038 Numeric |
|Smith Barney | (800) 225-0256 (#304655) Alpha |
|390 Greenwich Street - 6W | |
|New York, NY 10013 | E-mail: joseph_iacovelli @ smb.com |
+-----------------------------------------------------------------------+
| Careful what ya ask for old buddy it just might come true - Wolverine |
+-----------------------------------------------------------------------+