Security Incidents mailing list archives

Re: <victim>server formmail.pl exploit in the wild


From: Noel Rosenberg <nrosen04 () emerald tufts edu>
Date: Fri, 12 Apr 2002 15:39:56 -0400 (EDT)

On Thu, 11 Apr 2002, Andrew Daviel wrote:

|
| I've seen an attempt to exploit FormMail.pl version 1.9 (the latest
| official version), viz.

FormMail 1.9 (and lower) is insecure and should be replaced.

see Anonymous Mail Forwarding Vulnerabilities in FormMail 1.9
http://online.securityfocus.com/archive/1/252232

-Noel


----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management 
and tracking system please see: http://aris.securityfocus.com


Current thread: