[4148] in WWW Security List Archive

home help back first fref pref prev next nref lref last post

Re: E-mail

daemon@ATHENA.MIT.EDU (Joseph Iacovelli)
Tue Jan 28 09:49:45 1997

From: "Joseph Iacovelli" <joseph_iacovelli@smb.com>
Date: Tue, 28 Jan 1997 07:38:16 -0500
In-Reply-To: Kevin Gannon <kgannon@esiotrot.kst.dit.ie>
        "Re: E-mail" (Jan 25, 10:13am)
To: xande <xande@venus.rdc.puc-rio.br>
Cc: www-security@ns2.rutgers.edu
Errors-To: owner-www-security@ns2.rutgers.edu

On Jan 25, 10:13am, Kevin Gannon wrote:
> Subject: Re: E-mail
> On Fri, 24 Jan 1997, Evil Pete wrote:
>
> > >I'd like to know if this program exists...
> > >It's a program that u send an e-mail to someone...then.. it bring me back
> > >the passwd file... I'd like to know this...
> > >By xande
> >
> > it is bullshit  unless the email contain a executable and you are dumb
enough
> > to run it....
> >
>
> It is not bullshit if you are talking about UNIX boxes on older
> version of Sendmail it was possible to get the passwd file mailed
> out.
>
> Kev.


Kevin is right.  Check out some of the known SENDMAIL books out on the
street.  They talk about of the known problems of the older versions of
sendmail and how to correct them.  Also, might want to take a look
at anything posted from CERT.


							Joseph



-- 
+---------------------------+-------------------------------------------+
|Joseph Iacovelli           | Phone:  (212) 723-5921                    |
|UNIX Systems Engineer      | Beeper: (917) 812-7038 	       Numeric  |
|Smith Barney               |	      (800) 225-0256 (#304655) Alpha    |
|390 Greenwich Street - 6W  |                                           |
|New York, NY 10013         | E-mail: joseph_iacovelli @ smb.com        |
+-----------------------------------------------------------------------+
| Careful what ya ask for old buddy it just might come true - Wolverine |		
+-----------------------------------------------------------------------+

home help back first fref pref prev next nref lref last post