[17926] in bugtraq
Re: R: Majordomo filenames used as passwords
daemon@ATHENA.MIT.EDU (John Ritchie)
Tue Dec 5 13:30:20 2000
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Message-ID: <Pine.GSO.4.10.10012050738030.29308-100000@netserve.ous.edu>
Date: Tue, 5 Dec 2000 07:48:05 -0800
Reply-To: John Ritchie <ritchiej@OSSHE.EDU>
From: John Ritchie <ritchiej@OSSHE.EDU>
X-To: Raistlin <raist@CTRADE.IT>
To: BUGTRAQ@SECURITYFOCUS.COM
In-Reply-To: <046701c05d4a$bb4ca7a0$0200a8c0@raistlin>
On Sun, 3 Dec 2000, Raistlin wrote:
> > This was reported TWICE, by two different people, in 1995. None of the
> posts
> > even got a reply. The bug has been confirmed on a live majordomo 1.94.3
> and
> > the code looks the same for 1.94.5 (the latest).
>
> I was unable to reproduce this behaviour on a Majordomo 1.94.4
>
> Did you actually test it out on a 1.94.5 ? If so, they have reintroduced a
> bug...
>
> Raistlin
>
>
I can reproduce this on 1.94.5.
It also appears that issuing the "passwd" command changes only the
password in the listname.passwd file, not the admin_passwd entry in the
listname.config file.
John Ritchie