Bugtraq mailing list archives

Re: ISS Internet Scanner Cannot be relied upon for conclusive


From: casper () HOLLAND SUN COM (Casper Dik)
Date: Tue, 9 Feb 1999 23:02:39 +0100


Consider another interesting case - there are several sendmail exploits
(circa 8.6) which require hardware and platform-specific eggs.  We
obviously would have a hard time actually implementing these, and it would
be very difficult to make it reliable - so we do a banner check.

Why do you need an egg?  Just stuffing down too much data down
sendmail's throat will make it crash.  Connection closed - has bug.

Casper



Current thread: