Re: Help with hijacked sendmail

From: David Ford (dford@erisksecurity.com)
Date: 09/27/01


Message-ID: <3BB258F6.1070508@erisksecurity.com>
Date: Wed, 26 Sep 2001 18:38:46 -0400
From: David Ford <dford@erisksecurity.com>
To: focus-linux@securityfocus.com
Subject: Re: Help with hijacked sendmail

Mogens Valentin wrote:

>Thiago Conde Figueiro wrote:
>
>>Why not stop using sendmail altogether? Sendmail has a long, sad history
>>of exploits. Ever after I found out about Postfix (a secure replacement
>>for sendmail) my worries with smtp have dropped to almost zero.
>>
>Sure, but all it takes to make sendmail resonably secure is update to
>latest version and do somthing like:
>

Sendmail has had a very good recent reputation and out of the box
sendmail is a trusted MTA. Look carefully at the recent sendmail
advisories.

The moral of the story here isn't whether you're running postfix, exim,
qmail or sendmail. It's whether you're using an updated product.

Bugs are found and fixed. New methods of attack are discovered and more
bugs are found and fixed. Whether it is a denial of service or exploit,
it is still a problem and must be addressed.

The proper answer irrespective of the package in question is to keep
things updated.

David



Relevant Pages

  • RE: What version of BSD should I use
    ... > support in sendmail, ... > I think, older is better, but I will not have support for some new ... > Less bugs = BETTER and SAFER life. ... I haven't had any major problems running 4-stable, ...
    (freebsd-questions)
  • Re: which mta to choose
    ... >>time like every other MTA like Postfix, ... > YOu seem to suggest that Sendmail had roughly the same amount of security ... > issues and bugs as the other MTAs. ... Sendmail has a history of security ...
    (alt.os.linux)
  • sendmail 8.13.8 available
    ... Sendmail, Inc., and the Sendmail Consortium announce the availability ... as well as some other bugs. ... PLEASE REMEMBER THAT EXPORT/IMPORT AND/OR USE OF STRONG CRYPTOGRAPHY ... Avoid opening qf files if QueueSortOrder is "none". ...
    (comp.mail.sendmail)
  • [Full-disclosure] [ GLSA 200603-21 ] Sendmail: Race condition in the handling of asynchronou
    ... Bugs: #125623 ... Sendmail is vulnerable to a race condition which could lead to the ... Security is a primary focus of Gentoo Linux and ensuring the ...
    (Full-Disclosure)
  • [ GLSA 200603-21 ] Sendmail: Race condition in the handling of asynchronous signals
    ... Bugs: #125623 ... Sendmail is vulnerable to a race condition which could lead to the ... Security is a primary focus of Gentoo Linux and ensuring the ...
    (Bugtraq)