Bugtraq mailing list archives
Re: sendmail testing
From: yogo () math tau ac il (Yossi Gottlieb)
Date: Mon, 27 Feb 1995 00:47:56 +0200 (GMT+0200)
So what I'm confused about is this: What is different about the way sendmail processes the queue files when it is called with the -q option and when it is just processing off smtp connections? I see the exact same behavior on 8.6.9 running on 4.1.3 and Linux.
There's nothing different actually, the problem is the reading of the queue file which was spoofed. If the mail doesn't get queued (and gets delivered immediately) things are treated as they should, as any \n characters are treated as part of the strings. But if it ever gets down to the queue file, once being read any things get whole new meanings (\n breaks the strings). yossi (yogo () math tau ac il)
Current thread:
- Re: new sendmail bug? Quentin Fennessy (Feb 23)
- Bugtraq mailing list QM Admin (Feb 22)
- New Sendmail hole (w/IDENT?) John Adams (Feb 22)
- SGI patch for sendmail hole Dave Schweisguth (Feb 23)
- Re: new sendmail bug? Neil Woods (Feb 23)
- Bugtraq mailing list badbird () nether net (Feb 23)
- Forgery... Dave Horsfall (Feb 23)
- sendmail testing *Hobbit* (Feb 24)
- Re: sendmail testing Michael R. Widner (Feb 25)
- Re: sendmail testing Yossi Gottlieb (Feb 26)
- lpr/lpd problems Baba Z Buehler (Feb 26)
- the qf file *Hobbit* (Feb 25)
- <Possible follow-ups>
- Re: new sendmail bug? Michael Van Norman (Feb 23)