Re: lug-bg: Sendmail +SASL problem (unknown password verifier)

2003-03-11 Thread Teodor Georgiev


- Original Message -
From: "Vesselin Kolev" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Monday, March 10, 2003 9:06 PM
Subject: Re: lug-bg: Sendmail +SASL problem (unknown password verifier)


>   Dori TLS-a trygna. Eto edna ilustracia:
>
> Mar 10 21:20:00 Test sendmail[22721]: h2AJJxOd022721:
> from=<[EMAIL PROTECTED]>, size=399, class=0, nrcpts=1,
> msgid=<[EMAIL PROTECTED]>, proto=ESMTP, daemon=MTA,
> relay=e-lib.vpn.lcpe.uni-sofia.bg [192.168.100.111]
>
> Mar 10 21:20:00 Test sendmail[22724]: STARTTLS=client, relay=mail.dir.bg.,
> version=TLSv1/SSLv3, verify=OK, cipher=DES-CBC3-SHA, bits=168/168
>
> Mar 10 21:20:00 Test sendmail[22724]: h2AJJxOd022721:
> to=<[EMAIL PROTECTED]>, delay=00:00:00, xdelay=00:00:00,
mailer=esmtp,
> pri=30391, relay=mail.dir.bg. [194.145.63.28], dsn=2.0.0, stat=Sent
(16419523
> message accepted for delivery)
>
>
>   A koi beshe tozi deto kazvashe, che ne stavali i ne mozhelo???


Vinagi sym kazval, che niama tiasno dupe, a ima kriv h*i :)))
Za tova da se zamisli Trendafil Akaciev, kato psuva Sendmaila che ne trygval
s TLS, a Postfix trygnal :)






A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers).
http://www.linux-bulgaria.org - Hosted by Internet Group Ltd. - Stara Zagora
To unsubscribe: http://www.linux-bulgaria.org/public/mail_list.html



Re: lug-bg: Sendmail +SASL problem (unknown password verifier)

2003-03-10 Thread Teodor Georgiev

btw, oshte 2 vyprosa:

1. kakva ti e versiata na Cyrus SASL'to?
2. pokazhi si site.config.m4 faila ot koito si kompiliral.


- Original Message -
From: "Vesselin Kolev" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Monday, March 10, 2003 7:43 PM
Subject: lug-bg: Sendmail +SASL problem (unknown password verifier)


> -BEGIN PGP SIGNED MESSAGE-
> Hash: SHA1
>
> Zdraveite,
>
>Dosta sym si igral sys Cyrus SASL, no tozi pyt neshto ne stana.
>
>Napravih kompilacia na Sendmail 8.12.8. Kompiliraneto e s opcii
> - -DSASL i -DSTARTTLS i e uspeshno:
>
> [EMAIL PROTECTED] mail]# sendmail -d0 < /dev/null
> Version 8.12.8
>  Compiled with: DNSMAP LOG MATCHGECOS MIME7TO8 MIME8TO7 NAMED_BIND
> NETINET NETUNIX NEWDB PIPELINING SASLv2 SCANF STARTTLS USERDB
> XDEBUG
>
>  SYSTEM IDENTITY (after readcf) 
>   (short domain name) $w = localhost
>   (canonical domain name) $j = localhost.localdomain
>  (subdomain name) $m = localdomain
>   (node name) $k = Test
> 
>
> Prototipyt na faila sendmail.cf sendmail.mc ima v sebe si nuzhnite opcii
> za da raboti SASL authentikaciata:
>
> ...
> TRUST_AUTH_MECH(`EXTERNAL LOGIN PLAIN')dnl
> define(`confAUTH_MECHANISMS', `EXTERNAL LOGIN PLAIN')dnl
> ...
>
> Za proverka:
>
> [EMAIL PROTECTED] mail]# telnet localhost 25
> Trying 127.0.0.1...
> Connected to localhost.
> Escape character is '^]'.
> 220 localhost.localdomain ESMTP Sendmail 8.12.8/8.12.8; Mon, 10 Mar 2003
> 19:52:03 +0200
> EHLO localhost
> 250-localhost.localdomain Hello Test [127.0.0.1], pleased to meet you
> 250-ENHANCEDSTATUSCODES
> 250-PIPELINING
> 250-8BITMIME
> 250-SIZE
> 250-DSN
> 250-ETRN
> 250-AUTH LOGIN PLAIN
> 250-DELIVERBY
> 250 HELP
> quit
> 221 2.0.0 localhost.localdomain closing connection
> Connection closed by foreign host.
> [EMAIL PROTECTED] mail]#
>
> Vyv faila /usr/lib/sasl2/Sendmail.conf se postavia reda:
>
> pwcheck_method: saslauthd
>
> Sled tova se puska saslauthd
>
> /usr/sbin/saslauthd -n 0 -a PAM
>
> I na pryv pogled po syslog niama nikakvi problemi. Shtom obache
> ot vynshnia klient opitam udostoveriavane... to propada:
>
> sendmail[21880]: unknown password verifier
>
> =
>
>Niakoi da se e sblyskval s podoben problem i da znae kak da go
> reshi?
>
> =
>
>
>   Pozdravi
>  Vesselin Kolev
>
> -BEGIN PGP SIGNATURE-
> Version: GnuPG v1.2.1 (GNU/Linux)
>
> iD8DBQE+bM64+48lZPXaa+MRAuqdAKDE4SJOWALI+Y/gJVMSOU7tiunXRQCgtpxC
> +TCJYnb9RfT2rSypkY33fbg=
> =41dB
> -END PGP SIGNATURE-
>
>

> A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers).
> http://www.linux-bulgaria.org - Hosted by Internet Group Ltd. - Stara
Zagora
> To unsubscribe: http://www.linux-bulgaria.org/public/mail_list.html
>



A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers).
http://www.linux-bulgaria.org - Hosted by Internet Group Ltd. - Stara Zagora
To unsubscribe: http://www.linux-bulgaria.org/public/mail_list.html



Re: lug-bg: Sendmail +SASL problem (unknown password verifier)

2003-03-10 Thread Vesselin Kolev
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

> >
> > =
> >
> >Niakoi da se e sblyskval s podoben problem i da znae kak da go
> > reshi?
> >
> > =


  Otboi:)) Opravi se.. Problemyt beshe v tova, che ne biah startirah pwcheck
kato daemon. Sega veche vsichko si raboti normalno.

  Dori TLS-a trygna. Eto edna ilustracia:

Mar 10 21:20:00 Test sendmail[22721]: h2AJJxOd022721: 
from=<[EMAIL PROTECTED]>, size=399, class=0, nrcpts=1, 
msgid=<[EMAIL PROTECTED]>, proto=ESMTP, daemon=MTA, 
relay=e-lib.vpn.lcpe.uni-sofia.bg [192.168.100.111]

Mar 10 21:20:00 Test sendmail[22724]: STARTTLS=client, relay=mail.dir.bg., 
version=TLSv1/SSLv3, verify=OK, cipher=DES-CBC3-SHA, bits=168/168

Mar 10 21:20:00 Test sendmail[22724]: h2AJJxOd022721: 
to=<[EMAIL PROTECTED]>, delay=00:00:00, xdelay=00:00:00, mailer=esmtp, 
pri=30391, relay=mail.dir.bg. [194.145.63.28], dsn=2.0.0, stat=Sent (16419523 
message accepted for delivery)


  A koi beshe tozi deto kazvashe, che ne stavali i ne mozhelo???

   Blagodaria na Teodor Georgiev za otzivchivostta!

Pozdravi
  Vesselin Kolev
-BEGIN PGP SIGNATURE-
Version: GnuPG v1.2.1 (GNU/Linux)

iD8DBQE+bOJT+48lZPXaa+MRAuQ7AJ9kl8/vu/zbI/0bWCrOSGACdGgoAgCgmDok
mbVz5RuhAhlMDD/Fb2JR3sI=
=WrMJ
-END PGP SIGNATURE-


A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers).
http://www.linux-bulgaria.org - Hosted by Internet Group Ltd. - Stara Zagora
To unsubscribe: http://www.linux-bulgaria.org/public/mail_list.html



Re: lug-bg: Sendmail +SASL problem (unknown password verifier)

2003-03-10 Thread Vesselin Kolev
On Monday 10 Mar 2003 20:16, Teodor Georgiev wrote:
> Sendmaila ti e OK spored men.
> v PAM kak tochno relayvash avtentikaciata?
> Pokazhi redovete.
>

Eto:

[EMAIL PROTECTED] pam.d]# cat system-auth
#%PAM-1.0
# This file is auto-generated.
# User changes will be destroyed the next time authconfig is run.
authrequired  /lib/security/pam_env.so
authsufficient/lib/security/pam_unix.so likeauth nullok
authrequired  /lib/security/pam_deny.so

account required  /lib/security/pam_unix.so

passwordrequired  /lib/security/pam_cracklib.so retry=3 type=
passwordsufficient/lib/security/pam_unix.so nullok use_authtok md5
shadow
passwordrequired  /lib/security/pam_deny.so

session required  /lib/security/pam_limits.so
session required  /lib/security/pam_unix.so


  Pozdravi
Vesselin Kolev


A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers).
http://www.linux-bulgaria.org - Hosted by Internet Group Ltd. - Stara Zagora
To unsubscribe: http://www.linux-bulgaria.org/public/mail_list.html



Re: lug-bg: Sendmail +SASL problem (unknown password verifier)

2003-03-10 Thread Teodor Georgiev

Sendmaila ti e OK spored men.
v PAM kak tochno relayvash avtentikaciata?
Pokazhi redovete.

- Original Message -
From: "Vesselin Kolev" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Monday, March 10, 2003 7:43 PM
Subject: lug-bg: Sendmail +SASL problem (unknown password verifier)


> -BEGIN PGP SIGNED MESSAGE-
> Hash: SHA1
>
> Zdraveite,
>
>Dosta sym si igral sys Cyrus SASL, no tozi pyt neshto ne stana.
>
>Napravih kompilacia na Sendmail 8.12.8. Kompiliraneto e s opcii
> - -DSASL i -DSTARTTLS i e uspeshno:
>
> [EMAIL PROTECTED] mail]# sendmail -d0 < /dev/null
> Version 8.12.8
>  Compiled with: DNSMAP LOG MATCHGECOS MIME7TO8 MIME8TO7 NAMED_BIND
> NETINET NETUNIX NEWDB PIPELINING SASLv2 SCANF STARTTLS USERDB
> XDEBUG
>
>  SYSTEM IDENTITY (after readcf) 
>   (short domain name) $w = localhost
>   (canonical domain name) $j = localhost.localdomain
>  (subdomain name) $m = localdomain
>   (node name) $k = Test
> 
>
> Prototipyt na faila sendmail.cf sendmail.mc ima v sebe si nuzhnite opcii
> za da raboti SASL authentikaciata:
>
> ...
> TRUST_AUTH_MECH(`EXTERNAL LOGIN PLAIN')dnl
> define(`confAUTH_MECHANISMS', `EXTERNAL LOGIN PLAIN')dnl
> ...
>
> Za proverka:
>
> [EMAIL PROTECTED] mail]# telnet localhost 25
> Trying 127.0.0.1...
> Connected to localhost.
> Escape character is '^]'.
> 220 localhost.localdomain ESMTP Sendmail 8.12.8/8.12.8; Mon, 10 Mar 2003
> 19:52:03 +0200
> EHLO localhost
> 250-localhost.localdomain Hello Test [127.0.0.1], pleased to meet you
> 250-ENHANCEDSTATUSCODES
> 250-PIPELINING
> 250-8BITMIME
> 250-SIZE
> 250-DSN
> 250-ETRN
> 250-AUTH LOGIN PLAIN
> 250-DELIVERBY
> 250 HELP
> quit
> 221 2.0.0 localhost.localdomain closing connection
> Connection closed by foreign host.
> [EMAIL PROTECTED] mail]#
>
> Vyv faila /usr/lib/sasl2/Sendmail.conf se postavia reda:
>
> pwcheck_method: saslauthd
>
> Sled tova se puska saslauthd
>
> /usr/sbin/saslauthd -n 0 -a PAM
>
> I na pryv pogled po syslog niama nikakvi problemi. Shtom obache
> ot vynshnia klient opitam udostoveriavane... to propada:
>
> sendmail[21880]: unknown password verifier
>
> =
>
>Niakoi da se e sblyskval s podoben problem i da znae kak da go
> reshi?
>
> =
>
>
>   Pozdravi
>  Vesselin Kolev
>
> -BEGIN PGP SIGNATURE-
> Version: GnuPG v1.2.1 (GNU/Linux)
>
> iD8DBQE+bM64+48lZPXaa+MRAuqdAKDE4SJOWALI+Y/gJVMSOU7tiunXRQCgtpxC
> +TCJYnb9RfT2rSypkY33fbg=
> =41dB
> -END PGP SIGNATURE-
>
>

> A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers).
> http://www.linux-bulgaria.org - Hosted by Internet Group Ltd. - Stara
Zagora
> To unsubscribe: http://www.linux-bulgaria.org/public/mail_list.html
>



A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers).
http://www.linux-bulgaria.org - Hosted by Internet Group Ltd. - Stara Zagora
To unsubscribe: http://www.linux-bulgaria.org/public/mail_list.html



lug-bg: Sendmail +SASL problem (unknown password verifier)

2003-03-10 Thread Vesselin Kolev
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

Zdraveite,

   Dosta sym si igral sys Cyrus SASL, no tozi pyt neshto ne stana.

   Napravih kompilacia na Sendmail 8.12.8. Kompiliraneto e s opcii
- -DSASL i -DSTARTTLS i e uspeshno:

[EMAIL PROTECTED] mail]# sendmail -d0 < /dev/null
Version 8.12.8
 Compiled with: DNSMAP LOG MATCHGECOS MIME7TO8 MIME8TO7 NAMED_BIND
NETINET NETUNIX NEWDB PIPELINING SASLv2 SCANF STARTTLS USERDB
XDEBUG

 SYSTEM IDENTITY (after readcf) 
  (short domain name) $w = localhost
  (canonical domain name) $j = localhost.localdomain
 (subdomain name) $m = localdomain
  (node name) $k = Test


Prototipyt na faila sendmail.cf sendmail.mc ima v sebe si nuzhnite opcii
za da raboti SASL authentikaciata:

...
TRUST_AUTH_MECH(`EXTERNAL LOGIN PLAIN')dnl
define(`confAUTH_MECHANISMS', `EXTERNAL LOGIN PLAIN')dnl
...

Za proverka:

[EMAIL PROTECTED] mail]# telnet localhost 25
Trying 127.0.0.1...
Connected to localhost.
Escape character is '^]'.
220 localhost.localdomain ESMTP Sendmail 8.12.8/8.12.8; Mon, 10 Mar 2003 
19:52:03 +0200
EHLO localhost
250-localhost.localdomain Hello Test [127.0.0.1], pleased to meet you
250-ENHANCEDSTATUSCODES
250-PIPELINING
250-8BITMIME
250-SIZE
250-DSN
250-ETRN
250-AUTH LOGIN PLAIN
250-DELIVERBY
250 HELP
quit
221 2.0.0 localhost.localdomain closing connection
Connection closed by foreign host.
[EMAIL PROTECTED] mail]# 

Vyv faila /usr/lib/sasl2/Sendmail.conf se postavia reda:

pwcheck_method: saslauthd

Sled tova se puska saslauthd

/usr/sbin/saslauthd -n 0 -a PAM

I na pryv pogled po syslog niama nikakvi problemi. Shtom obache
ot vynshnia klient opitam udostoveriavane... to propada:

sendmail[21880]: unknown password verifier

=

   Niakoi da se e sblyskval s podoben problem i da znae kak da go
reshi?

=


  Pozdravi
 Vesselin Kolev

-BEGIN PGP SIGNATURE-
Version: GnuPG v1.2.1 (GNU/Linux)

iD8DBQE+bM64+48lZPXaa+MRAuqdAKDE4SJOWALI+Y/gJVMSOU7tiunXRQCgtpxC
+TCJYnb9RfT2rSypkY33fbg=
=41dB
-END PGP SIGNATURE-


A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers).
http://www.linux-bulgaria.org - Hosted by Internet Group Ltd. - Stara Zagora
To unsubscribe: http://www.linux-bulgaria.org/public/mail_list.html



lug-bg: sendmail - sasl

2003-03-05 Thread Niki Nick
Georgi Kupenov pishe  

>Predi da prodylvish borbata sys SASL
>tegli edin byrz upgrade an sendmail-a
>(nishto, che si s posledna versiq) :

Ami nali Systems Affected sa predi sendmail.8.12.8  ne vkluchitelno. I pri uslovie 
che sam go slozil 6to triabva da prava "upgrade an sendmail-a"

t.e. ima li fal6iva versia na sendmail.8.12.8  i ako da, 
ako imam:
71b4ce8276536b82d4acdf6ec8be306a sendmail.8.12.8.tar.gz
[EMAIL PROTECTED] md5sum sendmail.8.12.8.tar.gz
71b4ce8276536b82d4acdf6ec8be306a  sendmail.8.12.8.tar.gz

Znachi li che niamam problem s versiata.

Mersi predvaritelno.



-
http://kino.GBG.bg -  Всичко за киното

A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers).
http://www.linux-bulgaria.org - Hosted by Internet Group Ltd. - Stara Zagora
To unsubscribe: http://www.linux-bulgaria.org/public/mail_list.html



Re: lug-bg: sendmail - sasl - Remote Buffer Overflow in Sendmail

2003-03-05 Thread Georgi Kupenov
Nickola Kolev wrote:
 Georgi wrote:

[ cut ]
 > Predi da prodylvish borbata sys SASL
 > tegli edin byrz upgrade an sendmail-a
 > (nishto, che si s posledna versiq) :
 > 
 > -- Forwarded message --
 > Date: Mon, 3 Mar 2003 13:06:09 -0500
 > From: CERT Advisory <[EMAIL PROTECTED]>
 > To: [EMAIL PROTECTED]
 > Subject: CERT Advisory CA-2003-07 Remote Buffer Overflow in Sendmail
[ cut ]

Не стига, че за това вече говорихме преди два дни, 
Sorry, propusnal sym go qwno w sumatohata ...

ама да го пращаш и 
три пъти?
Pratil sym go SAMO wednyv.

Move da se widi datata i chasa na izprashtane
w header-ite na 4-te msg-ta,
koito sa polucheni w mailing list-a.
Inache prichinata za 4 wmesto edno pisma e slednata:
2003-03-05 12:41:33.280458500 delivery 2174049: deferral: 
Connected_to_212.5.145.46_but_connection_died._Possible_duplicate!_(#4.4.2)/
2003-03-05 13:01:45.540433500 delivery 2175234: deferral: 
Connected_to_212.5.145.46_but_connection_died._Possible_duplicate!_(#4.4.2)/
2003-03-05 13:30:27.720423500 delivery 2176890: deferral: 
Connected_to_212.5.145.46_but_connection_died._Possible_duplicate!_(#4.4.2)/

Pozdrawi!
--
Georgi Kupenov
[EMAIL PROTECTED]

A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers).
http://www.linux-bulgaria.org - Hosted by Internet Group Ltd. - Stara Zagora
To unsubscribe: http://www.linux-bulgaria.org/public/mail_list.html



Re: lug-bg: sendmail - sasl - Remote Buffer Overflow in Sendmail

2003-03-05 Thread Nickola Kolev
 Georgi wrote:

[ cut ]
 > Predi da prodylvish borbata sys SASL
 > tegli edin byrz upgrade an sendmail-a
 > (nishto, che si s posledna versiq) :
 > 
 > -- Forwarded message --
 > Date: Mon, 3 Mar 2003 13:06:09 -0500
 > From: CERT Advisory <[EMAIL PROTECTED]>
 > To: [EMAIL PROTECTED]
 > Subject: CERT Advisory CA-2003-07 Remote Buffer Overflow in Sendmail
[ cut ]

Не стига, че за това вече говорихме преди два дни, ама да го пращаш и 
три пъти?



Всичко най-хубаво,
Никола



pgp0.pgp
Description: PGP signature


Re: lug-bg: sendmail - sasl - Remote Buffer Overflow in Sendmail

2003-03-05 Thread Georgi Kupenov
Niki Nick wrote:
Privet grupa 

Slozih si sendmail.8.12.8  poslednia. No iskam da si pusna i SASL kam nego. Pochetoh tuk tam dokomentacia no ne6to ne mi se poluchava buildvaneto sas SASL. Shte pomolia ako niakoi gi polzva ako moze da mi opishe kak gi instalira i puska.
Predi da prodylvish borbata sys SASL
tegli edin byrz upgrade an sendmail-a
(nishto, che si s posledna versiq) :
-- Forwarded message --
Date: Mon, 3 Mar 2003 13:06:09 -0500
From: CERT Advisory <[EMAIL PROTECTED]>
To: [EMAIL PROTECTED]
Subject: CERT Advisory CA-2003-07 Remote Buffer Overflow in Sendmail


-BEGIN PGP SIGNED MESSAGE-

CERT Advisory CA-2003-07 Remote Buffer Overflow in Sendmail

   Original release date: March 3, 2003
   Last revised: --
   Source: CERT/CC
   A complete revision history can be found at the end of this file.

Systems Affected

 * Sendmail Pro (all versions)
 * Sendmail Switch 2.1 prior to 2.1.5
 * Sendmail Switch 2.2 prior to 2.2.5
 * Sendmail Switch 3.0 prior to 3.0.3
 * Sendmail for NT 2.X prior to 2.6.2
 * Sendmail for NT 3.0 prior to 3.0.3
 * Systems  running  open-source  sendmail  versions prior to 8.12.8,
   including UNIX and Linux systems
Overview

   There  is  a vulnerability in sendmail that may allow remote attackers
   to gain the privileges of the sendmail daemon, typically root.
I. Description

   Researchers  at  Internet  Security  Systems  (ISS)  have discovered a
   remotely  exploitable  vulnerability  in  sendmail. This vulnerability
   could  allow  an  intruder  to  gain  control of a vulnerable sendmail
   server.
   Most  organizations  have  a variety of mail transfer agents (MTAs) at
   various  locations  within their network, with at least one exposed to
   the   Internet.   Since   sendmail  is  the  most  popular  MTA,  most
   medium-sized  to  large  organizations are likely to have at least one
   vulnerable   sendmail   server.  In  addition,  many  UNIX  and  Linux
   workstations  provide  a  sendmail  implementation that is enabled and
   running by default.
   Thisvulnerabilityismessage-orientedasopposedto
   connection-oriented. That means that the vulnerability is triggered by
   the  contents  of  a  specially-crafted  email  message rather than by
   lower-level  network  traffic.  This  is important because an MTA that
   does  not  contain  the  vulnerability will pass the malicious message
   along  to  other  MTAs  that may be protected at the network level. In
   other  words, vulnerable sendmail servers on the interior of a network
   are  still  at risk, even if the site's border MTA uses software other
   than sendmail. Also, messages capable of exploiting this vulnerability
   may pass undetected through many common packet filters or firewalls.
   Sendmail has indicated to the CERT/CC that this vulnerability has been
   successfully  exploited in a laboratory environment. We do not believe
   that   this   exploit  is  available  to  the  public.  However,  this
   vulnerability  is  likely  to  draw  significant  attention  from  the
   intruder community, so the probability of a public exploit is high.
   A  successful  attack  against  an  unpatched sendmail system will not
   leave any messages in the system log. However, on a patched system, an
   attempt  to  exploit  this  vulnerability will leave the following log
   message:
 Dropped invalid comments from header address

   Although  this does not represent conclusive evidence of an attack, it
   may be useful as an indicator.
   A  patched  sendmail server will drop invalid headers, thus preventing
   downstream servers from receiving them.
   The CERT/CC is tracking this issue as VU#398025. This reference number
   corresponds to CVE candidate CAN-2002-1337.
   For more information, please see

   http://www.sendmail.org
   http://www.sendmail.org/8.12.8.html
   http://www.sendmail.com/security/
   http://www.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=21950
   http://www.kb.cert.org/vuls/id/398025
II. Impact

   Successful exploitation of this vulnerability may allow an attacker to
   gain  the  privileges  of  the  sendmail  daemon, typically root. Even
   vulnerable  sendmail servers on the interior of a given network may be
   at  risk  since  the vulnerability is triggered from the contents of a
   malicious email message.
III. Solution

Apply a patch from Sendmail

   Sendmail  has produced patches for versions 8.9, 8.10, 8.11, and 8.12.
   However,  the  vulnerability  also  exists  in earlier versions of the
   code;  therefore,  site  administrators  using  an earlier version are
   encouraged to upgrade to 8.12.8. These patches are located at
   ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.12.security.cr.patch

ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.11.6.security.cr.patch
   ftp://ftp.sendmail.org/pub/sendmail/sendmail.8.9.3.security.cr.patch
Apply a patch 

Re: Re: lug-bg: sendmail - sasl

2003-03-05 Thread Vesselin Kolev
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

Haide da ne pishem tintiri-mintiri, che TLS ne bil implementiran
za Sendmail

http://www.sial.org/sendmail/tls-relay/

Oglezhdate se, chetete i posle pishete. Stiga naprazen traffic i
IRC chat manieri i ploski opit za zaformiane na t.nar. flames.


On Wednesday 05 Mar 2003 11:54, Todor Belev wrote:
> Eiii,
> blagodaria na Vesselin za toia link.
> Navremto az syshto imah golemi myki da podkaram Sendmail-a s SMTP auth e ne
> stavashe i ne stavashe. Nakraia migrirah dosta uspeshno kym Postfix,
> preporychvam go na vsichki prosto e pesen i konfiguriraneto i security
> vsichko e na nivo- da ne govorim che imam TLSv1 predi oshte da se podade
> parolkata za SMTP auth, posle i cialaoto pismo zaminava kriptiranko.
> Vyobshte mnogo blaginki deto v sednmaila pylen sux.
>
-BEGIN PGP SIGNATURE-
Version: GnuPG v1.2.1 (GNU/Linux)

iD8DBQE+ZdIr+48lZPXaa+MRArlrAJ4lNzTOhAH0WIm1wjHWwvOtFUjwgwCg2lFN
ZTJMbmsby0I47OxO1N5ggM0=
=TqkN
-END PGP SIGNATURE-


A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers).
http://www.linux-bulgaria.org - Hosted by Internet Group Ltd. - Stara Zagora
To unsubscribe: http://www.linux-bulgaria.org/public/mail_list.html



Re: Re: lug-bg: sendmail - sasl

2003-03-05 Thread Todor Belev

Eiii, 
blagodaria na Vesselin za toia link.
Navremto az syshto imah golemi myki da podkaram Sendmail-a s SMTP auth e ne stavashe i 
ne stavashe.
Nakraia migrirah dosta uspeshno kym Postfix, preporychvam go na vsichki prosto e pesen 
i konfiguriraneto i security vsichko e na nivo- da ne govorim che imam TLSv1 predi 
oshte da se podade parolkata za SMTP auth, posle i cialaoto pismo zaminava kriptiranko.
Vyobshte mnogo blaginki deto v sednmaila pylen sux.

Todorin

 > Оригинално писмо 
 >От: Vesselin Kolev [EMAIL PROTECTED]
 >Относно: Re: lug-bg: sendmail - sasl
 >До: [EMAIL PROTECTED]
 >Изпратено на: 2003-03-05 11:25:29.0
 >--
 >-BEGIN PGP SIGNED MESSAGE-
 >Hash: SHA1
 >
 >Ima edin document napisan ot Teodor Georgiev po vyprosa.
 >Mozhesh da go namerish tuk:
 >
 >http://www.lcpe.uni-sofia.bg/linuxdoc/sendmail/sasl.txt
 >
 >  Pozdravi
 > Vesselin Kolev
 >
 >On Wednesday 05 Mar 2003 10:39, Niki Nick wrote:
 >> Privet grupa 
 >>
 >> Slozih si sendmail.8.12.8  poslednia. No iskam da si pusna i SASL kam
 >> nego. Pochetoh tuk tam dokomentacia no ne6to ne mi se poluchava buildvaneto
 >> sas SASL. Shte pomolia ako niakoi gi polzva ako moze da mi opishe kak gi
 >> instalira i puska.
 >>
 >> Sendmail instaliram po dva nachina:
 >> 1. [sendmail-8.12.8]$ sh Build -c
 >>[sendmail-8.12.8]$ su
 >>[sendmail-8.12.8]# pwd
 >>[sendmail-8.12.8]# make install
 >> ... taka polzvam staria konfig
 >>
 >> 2. Ot .../devtools/OS$ cp Linux ../Site/config.Linux.m4
 >>Ot .../sendmail/  piskam "sh Build"
 >>staria sendmail.mc fail go kopiram v ...cf/cf/ papkata
 >>posledno izglezda taka:
 >> divert(0)dnl
 >> VERSIONID(`$Id: generic-linux.mc,v 8.1 1999/09/24 22:48:05 gshapiro Exp $')
 >> OSTYPE(linux)dnl
 >> DOMAIN(generic)dnl
 >> FEATURE(`access_db', `hash -T /etc/mail/access.db')
 >> FEATURE(`blacklist_recipients')
 >> MAILER(local)dnl
 >> MAILER(smtp)dnl
 >>puskam "..cf/cf/sh Build sendmail.cf"  i
 >>   "..cf/cf/sh Build install-cf"
 >>   "..sendmail/sh Build install"
 >>   "..makemap/sh Build install" .. taka i za drugite.
 >>I ako e nuzno pravia promeni po novia etc/mail/sendmail.cf fail. Puskam
 >> sendmail taka: /usr/sbin/sendmail -f /etc/mail/sendmail.cf -bd -q15m
 >>
 >> Ako imam gre6ka v izlozenoto tuk 6te sam blagodaren ako niakoi me popravi.
 >> I ako moze da mi kaze kak da vloza i polzvaneto na SASL ... kakto i
 >> puskaneto mu.
 >>
 >>
 >>
 >>
 >> -
 >> http://kino.GBG.bg -  Всичко за киното
 >> ===
 >>= A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers).
 >> http://www.linux-bulgaria.org - Hosted by Internet Group Ltd. - Stara
 >> Zagora To unsubscribe: http://www.linux-bulgaria.org/public/mail_list.html
 >> ===
 >>=
 >-BEGIN PGP SIGNATURE-
 >Version: GnuPG v1.2.1 (GNU/Linux)
 >
 >iD8DBQE+Zb6V+48lZPXaa+MRAgFxAKDqq3X1Vfv1+JpWGOdbhpdSd8JOcwCgg4Eb
 >rLKPY2cC6koqTU6L/06ABMw=
 >=uTyx
 >-END PGP SIGNATURE-
 >
 >
 >A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers).
 >http://www.linux-bulgaria.org - Hosted by Internet Group Ltd. - Stara Zagora
 >To unsubscribe: http://www.linux-bulgaria.org/public/mail_list.html
 >
 >

-
http://kino.GBG.bg -  Всичко за киното

A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers).
http://www.linux-bulgaria.org - Hosted by Internet Group Ltd. - Stara Zagora
To unsubscribe: http://www.linux-bulgaria.org/public/mail_list.html



Re: lug-bg: sendmail - sasl

2003-03-05 Thread Vesselin Kolev
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

Ima edin document napisan ot Teodor Georgiev po vyprosa.
Mozhesh da go namerish tuk:

http://www.lcpe.uni-sofia.bg/linuxdoc/sendmail/sasl.txt

  Pozdravi
 Vesselin Kolev

On Wednesday 05 Mar 2003 10:39, Niki Nick wrote:
> Privet grupa 
>
> Slozih si sendmail.8.12.8  poslednia. No iskam da si pusna i SASL kam
> nego. Pochetoh tuk tam dokomentacia no ne6to ne mi se poluchava buildvaneto
> sas SASL. Shte pomolia ako niakoi gi polzva ako moze da mi opishe kak gi
> instalira i puska.
>
> Sendmail instaliram po dva nachina:
> 1. [sendmail-8.12.8]$ sh Build -c
>[sendmail-8.12.8]$ su
>[sendmail-8.12.8]# pwd
>[sendmail-8.12.8]# make install
> ... taka polzvam staria konfig
>
> 2. Ot .../devtools/OS$ cp Linux ../Site/config.Linux.m4
>Ot .../sendmail/  piskam "sh Build"
>staria sendmail.mc fail go kopiram v ...cf/cf/ papkata
>posledno izglezda taka:
> divert(0)dnl
> VERSIONID(`$Id: generic-linux.mc,v 8.1 1999/09/24 22:48:05 gshapiro Exp $')
> OSTYPE(linux)dnl
> DOMAIN(generic)dnl
> FEATURE(`access_db', `hash -T /etc/mail/access.db')
> FEATURE(`blacklist_recipients')
> MAILER(local)dnl
> MAILER(smtp)dnl
>puskam "..cf/cf/sh Build sendmail.cf"  i
>   "..cf/cf/sh Build install-cf"
>   "..sendmail/sh Build install"
>   "..makemap/sh Build install" .. taka i za drugite.
>I ako e nuzno pravia promeni po novia etc/mail/sendmail.cf fail. Puskam
> sendmail taka: /usr/sbin/sendmail -f /etc/mail/sendmail.cf -bd -q15m
>
> Ako imam gre6ka v izlozenoto tuk 6te sam blagodaren ako niakoi me popravi.
> I ako moze da mi kaze kak da vloza i polzvaneto na SASL ... kakto i
> puskaneto mu.
>
>
>
>
> -
> http://kino.GBG.bg -  Всичко за киното
> ===
>= A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers).
> http://www.linux-bulgaria.org - Hosted by Internet Group Ltd. - Stara
> Zagora To unsubscribe: http://www.linux-bulgaria.org/public/mail_list.html
> ===
>=
-BEGIN PGP SIGNATURE-
Version: GnuPG v1.2.1 (GNU/Linux)

iD8DBQE+Zb6V+48lZPXaa+MRAgFxAKDqq3X1Vfv1+JpWGOdbhpdSd8JOcwCgg4Eb
rLKPY2cC6koqTU6L/06ABMw=
=uTyx
-END PGP SIGNATURE-


A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers).
http://www.linux-bulgaria.org - Hosted by Internet Group Ltd. - Stara Zagora
To unsubscribe: http://www.linux-bulgaria.org/public/mail_list.html



lug-bg: sendmail - sasl

2003-03-05 Thread Niki Nick
Privet grupa 

Slozih si sendmail.8.12.8  poslednia. No iskam da si pusna i SASL kam nego. 
Pochetoh tuk tam dokomentacia no ne6to ne mi se poluchava buildvaneto sas SASL. Shte 
pomolia ako niakoi gi polzva ako moze da mi opishe kak gi instalira i puska.

Sendmail instaliram po dva nachina:
1. [sendmail-8.12.8]$ sh Build -c
   [sendmail-8.12.8]$ su
   [sendmail-8.12.8]# pwd
   [sendmail-8.12.8]# make install 
... taka polzvam staria konfig 

2. Ot .../devtools/OS$ cp Linux ../Site/config.Linux.m4
   Ot .../sendmail/  piskam "sh Build"
   staria sendmail.mc fail go kopiram v ...cf/cf/ papkata
   posledno izglezda taka:
divert(0)dnl
VERSIONID(`$Id: generic-linux.mc,v 8.1 1999/09/24 22:48:05 gshapiro Exp $')
OSTYPE(linux)dnl
DOMAIN(generic)dnl
FEATURE(`access_db', `hash -T /etc/mail/access.db')
FEATURE(`blacklist_recipients')
MAILER(local)dnl
MAILER(smtp)dnl
   puskam "..cf/cf/sh Build sendmail.cf"  i 
  "..cf/cf/sh Build install-cf"
  "..sendmail/sh Build install"
  "..makemap/sh Build install" .. taka i za drugite.
   I ako e nuzno pravia promeni po novia etc/mail/sendmail.cf fail. Puskam sendmail 
taka:
   /usr/sbin/sendmail -f /etc/mail/sendmail.cf -bd -q15m 

Ako imam gre6ka v izlozenoto tuk 6te sam blagodaren ako niakoi me popravi. I ako moze 
da mi kaze kak da vloza i polzvaneto na SASL ... kakto i puskaneto mu.   




-
http://kino.GBG.bg -  Всичко за киното

A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers).
http://www.linux-bulgaria.org - Hosted by Internet Group Ltd. - Stara Zagora
To unsubscribe: http://www.linux-bulgaria.org/public/mail_list.html