[2149] in bugtraq

home help back first fref pref prev next nref lref last post

Re: CERT Alert on new sendmail bug - any info?

daemon@ATHENA.MIT.EDU (Ben Golding)
Mon Aug 21 02:10:47 1995

Date:         Mon, 21 Aug 1995 11:10:16 +1000
Reply-To: Bugtraq List <BUGTRAQ@CRIMELAB.COM>
From: Ben Golding <bgg@connect.com.au>
X-To:         Bugtraq List <BUGTRAQ@CRIMELAB.COM>
To: Multiple recipients of list BUGTRAQ <BUGTRAQ@CRIMELAB.COM>
In-Reply-To:  Your message of "Fri, 18 Aug 1995 13:54:58 EDT."
              <199508181754.NAA08233@fnord.wang.com>

> It's a shame to have to give up IDA....  V8 doesn't do username-hiding
> nearly as well.

I have ported the IDA kit to sendmail 8.6.12, although it does require
a small patch to the source.  You can pick up the IDA extensions from
ftp.connect.com.au:pub/mail/sendmail.8.6.12.ida.tar.Z.

The patch changes some of sendmail-8's ruleset handling and I don't
believe it affects the underlying security of the program.

Username hiding works fine in this version.

        Ben.

home help back first fref pref prev next nref lref last post