Subject: Re: OK, so how do we slam shut this sendmail problem once and for all?
To: J.T. Conklin <jconklin@netcom.com>
From: Simon J. Gerraty <sjg@zen.void.oz.au>
List: current-users
Date: 09/02/1995 19:02:56
For what its worth, I did some testing the other day on some Sun boxes
to try and reproduce the syslog attack.
Sun's sendmail could easily be encouraged to dump core - suggesting
that if I could figure out the reight magic to send it, the attack
would work.
sendmail-8.6.12 on the other hand just reported "header line too long"
and was not troubled at all.
Actually I'd be interested in talking to anyone who has code that can
make an i386 or sparc do something via this mechanism...
--sjg