[8412] in Commercialization & Privatization of the Internet
Re: Independent Milnet
daemon@ATHENA.MIT.EDU (Christopher Davis)
Thu Nov 18 11:14:09 1993
Date: Thu, 18 Nov 1993 11:12:13 -0500
From: Christopher Davis <ckd@kei.com>
To: Mark-Ludwig@uai.com (Mark R. Ludwig)
Cc: com-priv@lists.psi.com
MRL> == Mark R Ludwig <Mark-Ludwig@uai.com>
MRL> If all this is in response to the most-recent sendmail problem, it
MRL> smells of over-reaction. The holes which the infamous worm
MRL> exploited acquired root privilege, and did it much more quietly.
MRL> This one can't acquire root directly, and the standard sendmail
MRL> configuration logs it all verbosely.$$
It's both over-reaction *and under-reaction*.
The most-recent sendmail security problem WORKS THROUGH FIREWALLS. It
might even work over BSMTP over UUCP, though I doubt it'd get through the
traditional UUCP 'rmail' program. You do NOT have to have a direct SMTP
connection to the target machine.
It's equivalent to changing the locks on your car to keep someone from
breaking the window to get in.
--
Christopher Davis * <ckd@kei.com> * (was <ckd@eff.org>) * MIME * RIPEM * [CKD1]