Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Sendmail and secure design
Jason Miller, 2006-05-01

Sendmail's wide market share, ancient code base and long vulnerability history make it an interesting example about the need for software to start from a secure design.

Comments Mode:
An Example 2006-05-02
Anonymous
Sendmail and root??? 2006-05-02
Anonymous
Sendmail and secure design 2006-05-02
Robert Banz (rob@nofocus.org)
I'm surprised that people are still going around saying "sendmail runs as root." Most operating systems that integrate sendmail now ship it running as another user (such as smmsp, sendmail, etc.) and leave the root-running to something less dangerous, such as the local delivery agent.

It's besides the point, however. It's still no excuse for shoddy programming -- and IMHO, sendmail is far from being shoddy programming today. The kinds of things you find now in sendmail (and other such packages) are obscure edge cases or strange operating system interactions -- on the other hand, 99.9% of the developers out there in the wild still can't fathom the concept of an SQL injection attack.

Picking on Sendmail is very late-'90s.


[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/400/33572#33572
Sendmail and secure design 2006-05-02
J. Lasser
Sendmail 2006-05-03
Alexey Vesnin
Sendmail and secure design 2006-05-03
Matthew Murphy
Sendmail and root??? 2 2006-05-09
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus