[17926] in bugtraq

home help back first fref pref prev next nref lref last post

Re: R: Majordomo filenames used as passwords

daemon@ATHENA.MIT.EDU (John Ritchie)
Tue Dec 5 13:30:20 2000

MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Message-ID:  <Pine.GSO.4.10.10012050738030.29308-100000@netserve.ous.edu>
Date:         Tue, 5 Dec 2000 07:48:05 -0800
Reply-To: John Ritchie <ritchiej@OSSHE.EDU>
From: John Ritchie <ritchiej@OSSHE.EDU>
X-To:         Raistlin <raist@CTRADE.IT>
To: BUGTRAQ@SECURITYFOCUS.COM
In-Reply-To:  <046701c05d4a$bb4ca7a0$0200a8c0@raistlin>

On Sun, 3 Dec 2000, Raistlin wrote:

> > This was reported TWICE, by two different people, in 1995. None of the
> posts
> > even got a reply. The bug has been confirmed on a live majordomo 1.94.3
> and
> > the code looks the same for 1.94.5 (the latest).
>
> I was unable to reproduce this behaviour on a Majordomo 1.94.4
>
> Did you actually test it out on a 1.94.5 ? If so, they have reintroduced a
> bug...
>
> Raistlin
>
>

I can reproduce this on 1.94.5.

It also appears that issuing the "passwd" command changes only the
password in the listname.passwd file, not the admin_passwd entry in the
listname.config file.

John Ritchie

home help back first fref pref prev next nref lref last post