Subject: Re: localhost security hole
To: Alan Barrett <apb@cequrux.com>
From: Andrew Brown <atatat@atatdot.net>
List: current-users
Date: 06/29/2003 01:04:00
>> Index: gnu/usr.sbin/sendmail/cf/cf/netbsd-msp.mc
>> @@ -2,4 +2,4 @@
>>  include(`../m4/cf.m4')
>>  VERSIONID(`@(#)netbsd-msp.mc   $Revision: 1.2 $')
>>  OSTYPE(bsd4.4)dnl
>> -FEATURE(`msp')dnl
>> +FEATURE(`msp', `[127.0.0.1]')dnl
>
>Thank you!  The above change to netbsd-msp.mc causes the following change to
>netbsd-msp.cf (which is also installed as /etc/mail/submit.cf):
>
>  -D{MTAHost}[localhost]
>  +D{MTAHost}[127.0.0.1]
>
>and, with that change, sendmail on my test system no longer connects to
>10.2.3.4 (which is the IP address of localhost.example.net in my test
>environment).

that may be, but it's specific to ipv4.  what about about ipv6
systems, where 127.0.0.1 is not a local ip address?  otoh, the name
localhost maps to an address in both spaces.

-- 
|-----< "CODE WARRIOR" >-----|
codewarrior@daemon.org             * "ah!  i see you have the internet
twofsonet@graffiti.com (Andrew Brown)                that goes *ping*!"
werdna@squooshy.com       * "information is power -- share the wealth."