Pyramid's sendmail

Karl Kleinpaste karl at triceratops.cis.ohio-state.edu
Sat Nov 12 02:21:28 AEST 1988


Try
	telnet 127.1 smtp
	[ready message from sendmail in SMTP]
	debug
and if it responds with
	200 Debug set
then your sendmail is subject to abuse.  The particular worm which
made the rounds was peculiar to VAXen and Sun3s, because it was
carrying around precompiled binaries for those 2 CPUs; but the general
problem of invoking debug mode remotely and then delivering to a piped
destination exists nonetheless.

csg at pyramid announced in the phage mailing list (discussing the worm,
its abortion, its consequences) that there exists a PTF to sendmail.

--Karl



More information about the Comp.sys.pyramid mailing list