[11712] in bugtraq
Re: I found this today and iam reporting it to you first!!! (fwd)
daemon@ATHENA.MIT.EDU (Bret Watson)
Tue Sep 7 11:47:35 1999
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Message-Id: <3.0.3.32.19990905110303.030db6e0@10.100.1.1>
Date: Tue, 7 Sep 1999 01:24:00 -0700
Reply-To: Bret Watson <ticm@POP.SOFTHOME.NET>
From: Bret Watson <ticm@POP.SOFTHOME.NET>
X-To: Daniel Dulitz <dulitz@valleytech.com>
To: BUGTRAQ@SECURITYFOCUS.COM
In-Reply-To: <14289.14131.519380.482752@enza.valleytech.com>
Exactly... however - many mail servers _are_ misconfigured. especially
those using an external-internal relay...
>Sit back and watch absolutely nothing happen, unless both mailers are
>misconfigured. Even the venerable RFC821
>(http://www.faqs.org/rfcs/std/std10.html) notes that:
>
> Of course, server-SMTPs should not send notification
> messages about problems with notification messages.
>
Technical Incursion Countermeasures
consulting@TICM.COM http://www.ticm.com/
voice mail/fax: (+65)459 6373(UTC+8 hrs)
The Insider - a e'zine on Computer security Call for papers Vol 3 Issue 2
http://www.ticm.com/info/insider/index.html