Re: Root shell vixie cron exploit

From: Christos Zoulas (christosat_private)
Date: Fri Sep 03 1999 - 18:42:22 PDT

  • Next message: Patrick Oonk: "[security-officerat_private: FreeBSD-SA-99:01: BSD File Flags"

    On Sep 1,  9:08pm, gvsat_private (Seva Gluschenko) wrote:
    -- Subject: Re: Root shell vixie cron exploit
    
    | The following address has permanent fatal errors:
    | -C/tmp/vixie-cf gvs
    |
    | So, sendmail _really_ refuses to accept -C key when run as root
    
    You've reached the wrong conclusion. *BSD's cron uses -t and passes
    recipients through stdin (which is TRT), instead of kluges to parse
    MAILTO and ignore things that start with -.
    
    christos
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 15:01:43 PDT