Re: linux box compromised: advice needed

From: Bill Unruh (unruh@physics.ubc.ca)
Date: 03/25/02

  • Next message: Dankin: "ipchains log"

    From: unruh@physics.ubc.ca (Bill Unruh)
    Date: 25 Mar 2002 20:58:02 GMT
    
    

    In <3C9ED0E1.610E609B@privacy.net> Rob MacGregor <me@privacy.net> writes:

    ]David wrote:

    ]> Also if you need to run a mail server upgrade sendmail to the newest
    ]> version which is "8.12.2" or possibly switch to a more secure MTA like
    ]> qmail or one of the others.

    ]Please don't spread FUD, sendmail is hardly insecure.

    The design of sendmail is suspect-- it is a monolitic suid program.
    Making sure you have caught all possible security faults is difficult,
    as is evidenced by the fact that sendmail is now over 20 years old, and
    still security flaws show up relatively regularly. Less often now than
    befor admitedly.

    ]Take a look at www.securityfocus.com and see how many vulnerabilities are listed.
    ]Sendmail 8.11 lists a whole 3 problems. All require local access - one doesn't
    ]even have any known exploit and another is "only" a DoS. Pretty unlikely to have
    ]been the cause of a *remote* exploit...

    ]The latest version recorded in their database (8.12.1, behind the times) doesn't
    ]even list any vulnerabilities.

    ]Sure, sendmail *used* to be insecure, but that's ancient history.

    Not that ancient, and the design is worrysome.



    Relevant Pages

    • Re: PGP and sendmail
      ... handle automatic encryption and decryption of e-mail through sendmail? ... I suppose you could design a system that automatically handles this ... for something that works with PGP for users to use with their sendmail ... Scheme Programming is subtle; subtlety can be hard. ...
      (comp.mail.sendmail)
    • Re: Unix program that sends email directly using MX record
      ... The poor security history is there, ... funnel design and conf files that require a scripting language are ... Sendmail has had TONS of remote vulnerabilities. ... qmail has never had a remote root vulnerability or a similar flaw ...
      (freebsd-questions)

  • Quantcast