PDA

View Full Version : Sendmail Exploit


Rodzilla
03-04-2003, 06:43 PM
Has it been patched yet?

admin
03-04-2003, 06:45 PM
All cpanel servers have been patched

way2real
03-04-2003, 09:35 PM
What is "sendmail exploit"?

Nedani
03-05-2003, 10:12 AM
Exploit (stress on the second syllable):
1. A vulnerability in software that can be used for breaking security or otherwise attacking an Internet host over the network.
2. A program/script that exploits (uses) an exploit defined above.

The attack is performed by an email message and occurs when the Sendmail server tries to parse the header of an incoming mail message. If that header is specially crafted then Sendmail is tricked to run hacker's instructions, which will be executed with administrator rights.

You can find the program on any hacking related website, and any kid or socially retarded guy (and there are so many of them) can use it to make your life miserable if you don't have the patch.

admin
03-09-2003, 12:02 AM
Just an update on this issue:

Cpanel servers were updated, however, the sendmail service does not actually run on Cpanel servers. Sendmail is just linked over to the real mail program. So this was not an issue.

Ensim servers were vulnerable, however, they have also been patched at this point.