Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Sendmail and secure design
Jason Miller, 2006-05-01

Sendmail's wide market share, ancient code base and long vulnerability history make it an interesting example about the need for software to start from a secure design.

Comments Mode:
An Example 2006-05-02
Anonymous
Sendmail and root??? 2006-05-02
Anonymous
Sendmail and secure design 2006-05-02
Robert Banz (rob@nofocus.org)
Sendmail and secure design 2006-05-02
J. Lasser
Sendmail 2006-05-03
Alexey Vesnin
It's a good point to find, describe and determine the bug/inconvinience or just a mistype in application - we're ALL humans, not the bots. We have a right to make mistakes sometimes, but don't all the times. Remember Windows XP SP1 - yes, there were alot of good bugfixes, adding two time more problems at the same time. Open Source software is not intended to turn the developers into monyless class - but for the good it removes the money-making as a goal at all. Sendmail is a very good example that if the TASK ITSELF becomes the aim, the algorithm of program overcomes the algorithms of sales - the things are going good. For a really long time. And they will be - in case of Sendmail. The key goal is to trust a right programs - and that's the POINT. Why do we trust a closed-source software? Yes, the good closed source software CAN exist - but it's always OpenStandart one(for example - Sophos Anti-Virus). If the developer has only thoughts about robbin' you again with a next patch or feature-pack - why do we trust him? Absurd question, with more unlogical answer - BUT WE DO.... OpenSource is not "just better because it is" - it's just OPEN for you. You want to add/change or tune up something - you welcome! You wish to understand how EXACTLY does it works - you welcome... And you can always suggest something and you'll be HEARD and your opinion will be taken in count. Why don't we stop trusting a black boxes of ClosedSource/ClosedStandart products right NOW? Or are we too used to do such a restless things?

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/400/33574#33574
Sendmail and secure design 2006-05-03
Matthew Murphy
Sendmail and root??? 2 2006-05-09
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus