Berkeley CSUA MOTD:Entry 27592
Berkeley CSUA MOTD
 
WIKI | FAQ | Tech FAQ
http://csua.com/feed/
2025/05/24 [General] UID:1000 Activity:popular
5/24    

2003/3/4-6 [Computer/SW/Mail] UID:27592 Activity:very high
3/3     There's a new sendmail root-exploit out there.  Time to patch/upgrade.
        (soda isn't vulnerable, but anyone running versions below 8.12 are)
        \_ Incorrect.  Every version since 5.19 or something is vulnerable
           up to and including 8.12.7.  Looks like soda still needs to be
           upgraded.  There's a patch out from FreeBSD, plus patches and
           8.12.8 distributions at http://sendmail.org.  Please correct your
           misinformation.  -- randal <rand@sendmail.com>
           \_ soda was patched with a 8.12.6 patch.
        \_ Email to root.
        \_ So what? Sendmail is so buggy wrt security that it might as well
           have been written by M$ code monkeys. If you want a secure mail
           server try postfix or qmail.
                \_ yeah, that's what, the second root hole in the past 3
                   years! what a piece of shit!
                   \_ yes. use qmail.
                        \_ you're deluding yourself if you think that qmail
                           wouldn't have just as many security problems if
                           it were as widely used as sendmail.  Reference:
                           Theo and openssh.  -tom
                           \_ Meaning what?  That as openssh became more
                              popular more holes were discovered or that theo
                              is a jerk so we should all not like openssh?
                              \_ Theo is specifically a jerk who used to
                                 crow all the time about how secure his
                                 software was, then when it became more
                                 popular more holes were discovered.  The
                                 exact same thing would happen with qmail
                                 if djb ever tried to make it into a
                                 generally useful program.  -tom
                                 \_ So exactly how many remote root holes
                                    have been discovered in OpenSSH in
                                    the default config? Exactly 1. How
                                    many in OpenBSD's 7 yr history?
                                    Exactly 1. Theo might be an ass but
                                    his software is secure. Same for DJB.
                                    Coding secure software requires a
                                    particular mindset that the people
                                    working on Sendmail (and Bind) don't
                                    have.
                                    \_ since November 2001, there have been
                                       three remote root and two local root
                                       holes found in openssh--that's far
                                       worse than sendmail over the same
                                       period.  -tom
                \_ tom, you make somewhat of a valid point, but i'm not talking
                   about theo here, i'm talking about djb. qmail is the #2 MTA.
                   how many qmail exploits have there been? besides, even if
                   you are right, in practice it is still less vulnerable bc
                   it is less targeted. the way i see it:
                   unix is to windows as qmail is to sendmail.
                   windows is more targeted, dumber people use windows, and
                   windows is generally easier to find holes in.
                   \_ I'm sure qmail is not the #2 MTA--#1 and #2 have to be
                      sendmail and Exchange.  In any case, it may be true that
                      qmail is inherently more secure than sendmail, but if so,
                      it's at least partly because of design decisions which
                      make qmail difficult to use in the real world. -tom
                      \_ Exchange?  I guess technically it's an MTA but using
                         Exchange in the same sentence as "security" seems
                         pointless.  Anyway, I agree qmail sucks to use in the
                         real world.  Actually it more than sucks.
                         \_ Qmail doesn't suck any worse than sendmail.
                            People are just so used to the pointless
                            complexity of sendmail that they don't really
                            notice it. Has anyone written a 500 page book
                            on how to use qmail? No. This is because it is
                            not as hard to use. -ausman
                            \_ don't be silly--qmail's configuration is
                               simpler than sendmail's, but it doesn't
                               support anything near the same level of
                               configurability.  -tom
                                \_ And for most folks a standard install of
                                   sendmail works fine, btw.  qmail requires
                                   all sorts of tedious bullshit.  So although
                                   making any serious changes to sendmail can
                                   be nearly impossible, most people won't need
                                   to anyway.
                                   \_ installing qmail is a breeze. the
                                      only tedious bullshit here is your
                                      comment. --aaron
                            \_ Having used both extensively I'll simply
                               disagree as a matter of personal choice.
                               Sendmail is bad but qmail is worse.
2025/05/24 [General] UID:1000 Activity:popular
5/24    

You may also be interested in these entries...
2010/4/7-8 [Computer/SW/Mail] UID:53776 Activity:nil
4/7     postfix equivalent of 'sendmail -bt' ?
	...
2008/7/15-16 [Computer/Domains] UID:50572 Activity:nil
7/14    Help sendmail experts. I forward email from my own domain to
        http://gmail.com. I have never had any problem until recently. The problem
        happens only when eBay sends an email to my domain (as
        member@ebay.com). I receive the mail on my domain/my machine, and
        when it tries to forward to gmail, I get the following:
         Diagnostic-Code: X-Postfix; host <DEAD>gmail-smtp-in.l.google.com<DEAD>[w.x.y.z]
	...
2006/12/29-30 [Computer/SW/Security, Academia/Berkeley/CSUA/Motd] UID:45510 Activity:high
12/29   There have been a lot of complaints regarding soda reliability and
        users not volunteering their time and effort to help. Obviously,
        it wouldn't make sense for every user to be given root access so
        they can volunteer. Instead, why don't we use motd for people to
        contribute concrete suggestions (not just to start flame wars) to
        improve soda reliability and security? I'll start:
	...
2006/9/9-11 [Computer/SW/Mail, Computer/SW/Unix] UID:44331 Activity:nil
9/9     After rotating my /var/log/mail.* files and restarting postfix,
        I no longer have any mail log files in /var/log/mail.*! Is there
        something else I have to do for postfix? I never had this problem
        when I was using sendmail. Please help!         -learning unix
        \_ man -k syslog
	...
2006/8/6-10 [Computer/SW/Mail] UID:43922 Activity:nil
8/5     I just want to take this fine opportunity and say, FUCK sendmail.
        It is difficult to configure and its debugging facility totally
        blows. I can't believe how braindead sendmail config is, not to
        mention its sucky security. Fuck sendmail, use postfix instead.
        I got postfix running in a jiffy and I didn't even have to go
        through 800 pages of sendmail manpage. Fuck sendmail and
	...
2006/8/4-6 [Computer/SW/Mail] UID:43896 Activity:nil
8/3     I'm trying to add virtual forwarding, by adding a file called
        /etc/mail/virtusertable that forwards from user "test@mydomain.com"
        to "joeblow". I also added the line "FEATURE(`virtusertable')dnl"
        in sendmail.mc. Lastly, I did a make, then restarted sendmail. However
        it is not working. How do I diagnose the problem?
        \_ I have a similar setup.  From my config I also have a
	...
2006/8/4-6 [Computer/SW/Mail] UID:43903 Activity:low
8/4     In sendmail on Linux, how do I write a rule which will quietly discard
        e-mail sent to nonexistent users? Default behavior is to bounce
        the mail back, but in the case of SPAM the From: address doesn't
        exist. I'd rather just toss such mail.
        \_ This may bring other problems with it, but you may wish to
           consider greylisting.  It simply replies to each mail with a 405
	...
2006/8/4-6 [Computer/SW/Mail, Computer/SW/OS/Linux] UID:43910 Activity:nil
8/4     After trying to get sendmail's virtusertable to work for several
        hours, I've given up and decided to use exim4 instead. I've followed
        the following URL for exim4's equivalent of virtusertable, but now
        wondering how I can specify "error: User Known" and email
        nullification inside my new /etc/exim/virtusertable?
        http://www.exim.org/pipermail/exim-users/Week-of-Mon-20030127/049071.html
	...
2006/8/4-6 [Computer/SW/Mail] UID:43914 Activity:nil
8/4     are exim-virtuser-person and sendmail-virtuser-person the same?
	...
2006/8/4-6 [Computer/SW/Mail] UID:43915 Activity:nil
8/4     Dear sendmail virtusertable gurus, please help.
        Let's say my domain name is <DEAD>csua1.com<DEAD> and I'd like it to handle mail
        for <DEAD>csua2.com<DEAD> as well. The virtusertable (which I ran "makemap hash"
        on to generate virtusertable.db) contains the followings:
        a@csua1.com joe
        b@csua2.com joe
	...
2006/8/5-6 [Computer/Domains] UID:43917 Activity:nil
8/5     I'm trying to setup procmail so that when I send email out, I can set my
        domain to be any of the 3 I own. However, sendmail keeps masquerading my
        domain to be a certain domain, even though I didn't specify masquerading
        in sendmail.mc/cf. What is going on?
        \_ Try Hotmail.  -proud American
	...
Cache (519 bytes)
sendmail.org
We would like to thank Manabu Kondo and the staff at IIJ for bringing this to our attention. Compiling and Configuration pages, before asking questions of the sendmail maintainers. E-mail Addresses for contributions, patches, feature requests, questions, and bug-reports. These contributions may be in form of patches, especially for feature requests, feedback about problems, and suggestions for enhancements. The Sendmail Consortium also thanks Bob Madderra of Southern Energy for donating the milter related domains.
Cache (317 bytes)
sendmail.com
Sendmail Mailstream Manager Bringing Message Management Under Control Manage your mail at perimeter, server and desktop. You get security against spam, viruses and denial of service attacks. It also can ensure regulatory compliance and enhance productivity by setting rules for message sorting, routing and archiving.