>>To prevent this exploit from happening I need to ENABLE
>>"EnableBangPath"?
>>What will happen when support is dropped in a future release?
>>Will it then still translate or will it refuse the mail?

To prevent this "exploit" (it is not a bug, it's a rarely used feature, which 
you
decided not to disable), you have to follow the tips from JP:

--------------------------
Betreff: [Assp-test] ASSP involved in relaying exploit for Sendmail
Absender: [EMAIL PROTECTED] (JP van Melis)
Datum: 26.02.2008, 11:05
Anhänge: <none>
--------------------------

I have disabled UUCP on my sendmail, so it will not relay to another domain,
but it will accept it as mail for itself.

http://safari.oreilly.com/1565928393/sendmail3-CHP-4-SECT-7

Don't assume UUCP support and UUCP relaying are turned off by default.
Always use the nouucp feature (FEATURE(nouucp)) to disable UUCP unless you
actually support UUCP: 

FEATURE(`nouucp')            recommended through V8.9
FEATURE(`nouucp',`reject')  recommended with V8.10 and above


--  
Matti Haack - Hit Haack IT Service Gmbh
Poltlbauer Weg 4, D-94036 Passau
+49 851 50477-22 Fax: +49 851 50477-29
http://www.haack-it.de

Registergericht Passau HRB 5678
USt. ID: DE195625715



Besuchen Sie jetzt unseren neuen INTERNET&NETWORK Security Shop mit 
faszinierenden Angeboten rund um Ihre Netzwerk- Sicherheit:
http://www.inn.de 


-- Ausgehende E-Mail wurde auf Viren gescannt  --


-------------------------------------------------------------------------
This SF.net email is sponsored by: Microsoft
Defy all challenges. Microsoft(R) Visual Studio 2008.
http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/
_______________________________________________
Assp-test mailing list
Assp-test@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/assp-test

Reply via email to