Re: serious Qpopper 3.0 vulnerability

From: M. Adam Kendall (makat_private)
Date: Wed Dec 01 1999 - 10:12:39 PST

  • Next message: Brock Tellier: "Re: [Re: Several FreeBSD-3.3 vulnerabilities]"

    On 30-Nov-1999 Josh Higham wrote:
    >>PS: The installation file suggests to run qpopper without tcpd, e.g.:
    >>pop3 stream tcp nowait root /usr/local/lib/qpopper qpopper -s
    >>I would NOT suggest doing it that way. Use:
    >
    > Does anyone know why qpopper suggests running without wrappers?
    
    It doesn't suggest running it without wrappers.. it just doesn't suggest
    that you DO.  Like most documentation, it doesn't assume you are running
    anything but their software, and therefore doesn't specifically mention
    the use of wrappers. How are they supposed to know that YOU (specifically)
    happen to have something else installed?
    
    Hell, even those vendors that DO know you have wrappers installed
    don't mention anything about it.  Those are the folks that you should
    be 'scolding'.  Just as a case in point, from a stock RH6.1 box:
    #linuxconf stream tcp wait root /bin/linuxconf linuxconf --http
    
    *sigh*
    
    --
    M. Adam Kendall         |
    makat_private           |  "There's never enough time to do
    http://kha0s.org        |  all the nothing you want."
                            |   --Bill Watterson (Calvin and Hobbes)
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 15:16:20 PDT