Vulnerability Development mailing list archives

Re: procmail / Sendmail - five bugs


From: fygrave () EPR0 ORG (CyberPsychotic)
Date: Sat, 15 Jan 2000 08:17:16 +0500


~: O MaxDaemonChildren=15 will avoid system crash and host rebooting but
~: not  sendmail  DoS,  because  sendmail will not accept any connection
~: until  "frozen" child processes will be killed. The best way to avoid
~: this vulnerability is to switch off ETRN feature by
~: O PrivacyOptions=noetrn

 or rather:

O PrivacyOptions=goaway

to be more hostile towards doorknockers.

-F


Current thread: