[8412] in Commercialization & Privatization of the Internet

home help back first fref pref prev next nref lref last post

Re: Independent Milnet

daemon@ATHENA.MIT.EDU (Christopher Davis)
Thu Nov 18 11:14:09 1993

Date: Thu, 18 Nov 1993 11:12:13 -0500
From: Christopher Davis <ckd@kei.com>
To: Mark-Ludwig@uai.com (Mark R. Ludwig)
Cc: com-priv@lists.psi.com

MRL> == Mark R Ludwig <Mark-Ludwig@uai.com>

 MRL> If all this is in response to the most-recent sendmail problem, it
 MRL> smells of over-reaction.  The holes which the infamous worm
 MRL> exploited acquired root privilege, and did it much more quietly.
 MRL> This one can't acquire root directly, and the standard sendmail
 MRL> configuration logs it all verbosely.$$

It's both over-reaction *and under-reaction*.

The most-recent sendmail security problem WORKS THROUGH FIREWALLS.  It
might even work over BSMTP over UUCP, though I doubt it'd get through the
traditional UUCP 'rmail' program.  You do NOT have to have a direct SMTP
connection to the target machine.

It's equivalent to changing the locks on your car to keep someone from
breaking the window to get in.
-- 
Christopher Davis * <ckd@kei.com> * (was <ckd@eff.org>) * MIME * RIPEM * [CKD1]

home help back first fref pref prev next nref lref last post