, 2006-05-01
Sendmail's wide market share, ancient code base and long vulnerability history make it an interesting example about the need for software to start from a secure design.
Expand all |
Post comment
|
Sendmail and secure design
, 2006-05-01 Sendmail's wide market share, ancient code base and long vulnerability history make it an interesting example about the need for software to start from a secure design.
Expand all |
Post comment
|
|
|
Privacy Statement |
It's besides the point, however. It's still no excuse for shoddy programming -- and IMHO, sendmail is far from being shoddy programming today. The kinds of things you find now in sendmail (and other such packages) are obscure edge cases or strange operating system interactions -- on the other hand, 99.9% of the developers out there in the wild still can't fathom the concept of an SQL injection attack.
Picking on Sendmail is very late-'90s.
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/columns/400/33572#33572