Re: [Plugins-writers] Sendmail < 8.13.5 race condition remote detect?

From: M sheffield (sheffield88@private)
Date: Tue May 02 2006 - 18:26:15 PDT


On 4/26/06, Renaud Deraison <deraison@private> wrote:
>
> It is possible to distinguish a patched and unpatched server, however
> the default timeout for this operation on many sendmail servers is
> set to 3600 seconds, which makes such a plugin impractical. Also, a
> banner check definitely is out of the question since every vendor
> backported the fixes (and compiling sendmail is no fun).
>

According to the Sun Advisory
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102262-1:

"The Solaris 9 and 10 patches which address this issue will update
sendmail directly to version 8.13.6+Sun"

That would seem to make a banner check worthwhile.
_______________________________________________
Plugins-writers mailing list
Plugins-writers@private
http://mail.nessus.org/mailman/listinfo/plugins-writers



This archive was generated by hypermail 2.1.3 : Tue May 02 2006 - 18:34:09 PDT