Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 24 Nov 1996 18:41:53 -0600 (CST)
From:      peter@taronga.com (Peter da Silva)
To:        hackers@freebsd.org
Subject:   Re: Replacing sendmail (Re: non-root users binding to ports < 1024 (was: Re: BoS: Exploit for sendmail smtpd bug (ver. 8.7-8.8.2
Message-ID:  <199611250041.SAA08169@bonkers.taronga.com>
In-Reply-To: <199611250006.KAA25958@genesis.atrad.adelaide.edu.au> from "Michael Smith" at Nov 25, 96 10:36:57 am

next in thread | previous in thread | raw e-mail | index | archive | help
> "Sendmail is the de-facto Unix standard mail delivery agent.  Is is
>  continually subjected to rigorous security scrutiny and frequently
>  updated.

Don't make me laugh. It has more security holes revealed per year than
every other setuid program in UNIX put together.

>  - expose a pile of security holes that the Qmail developer(s) never
>    thought existed.

Have you looked at qmail? The bits exposed to the outside world don't
even run as root. EVER.

>  - make FreeBSD the laughing stock of the unix community.

The part of the UNIX community that doesn't care about security, anyway.



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?199611250041.SAA08169>