Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Sendmail and secure design
Jason Miller, 2006-05-01

Sendmail's wide market share, ancient code base and long vulnerability history make it an interesting example about the need for software to start from a secure design.

Comments Mode:
An Example 2006-05-02
Anonymous
Sendmail and root??? 2006-05-02
Anonymous
Sendmail and secure design 2006-05-02
Robert Banz (rob@nofocus.org)
Sendmail and secure design 2006-05-02
J. Lasser
Sendmail 2006-05-03
Alexey Vesnin
Sendmail and secure design 2006-05-03
Matthew Murphy
Sendmail and root??? 2 2006-05-09
Anonymous
Agree with the anonymous poster of "Sendmail and root???"...

I guess sendmail is primarily used on gateways and thefor DON'T need to be root. There are a few scenarios where you need to runs as root. Like for example with local dielivery. But why do that on a gateway?

/P

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/400/33586#33586







 

Privacy Statement
Copyright 2009, SecurityFocus