RE: Qmail vs. postfix

From: multics@ruserved.com
Date: 08/10/01


From: multics@ruserved.com
Message-Id: <200108101732.f7AHWFT18289@multics.ruserved.com>
Subject: RE: Qmail vs. postfix 
To: security-basics@securityfocus.com
Date: Fri, 10 Aug 2001 13:32:15 -0400 (EDT)


> From: Gary Wilson [mailto:gwilson@one2one.co.uk]
>
> That's intetesting... I was under the impression that a large cash
> reward was available for anyone proving any security issues with
> qmail and repeatedly exploiting it. I further understand this
> reward has never been claimed? Can you post details (URLs,
> case notes etc) of these exploits etc so I can check my own qmail
> machines.

There is a difference between a security exploit and a denial of service.
What you describe is a denail of service. The attacker does not get
any access to the system.

-- 
Richard Shetron  multics@ruserved.com multics@acm.rpi.edu  NO UCE
What is the Meaning of Life?      There is no meaning,
It's just a consequence of complex carbon based chemistry; don't worry about it
The Super 76, "Free Aspirin and Tender Sympathy", Las Vegas Strip.



Relevant Pages

  • Re: [SLE] MTA Selection
    ... > security is an absolute requirement. ... qmail works right out of the box.. ... a lot smaller than Sendmail or Postfix. ... "It uses two large monolithic configuration files, ...
    (SuSE)
  • Re: [SLE] MTA Selection
    ... security is an absolute requirement. ... > secure, yes, but all the patches you need to use it in the 21st ... qmail works right out of the box.. ... a lot smaller than Sendmail or Postfix. ...
    (SuSE)
  • Re: linux box compromised: advice needed
    ... > stapling new features onto it, ... > security review and control. ... And that's why SMTP-Auth and STARTTLS for qmail are third-party patches ...
    (comp.os.linux.security)
  • Re: FreeBSD more secure than Linux
    ... > When the grand qmail challenge was put out, ... > of a class that could lead to a security breach) would be accepted. ... > of standard that will cause serious failure on at least one known system ...
    (comp.security.unix)
  • Re: How to replace sendmail with postfix?
    ... >> in all sorts of ways, making it unsuitable for serious MTA use in ... >> todays internet. ... > which has a history of security vulnerabilities as long as your arm. ... Not just because of qmail, but it was a large part ...
    (comp.unix.bsd.freebsd.misc)