Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Page 1 of 2 1 2 LastLast
Results 1 to 15 of 29
  1. #1
    Member
    Join Date
    Oct 2002
    Posts
    94

    Default sendmail vuln.

    http://www.msnbc.com/news/880094.asp?0cv=CB10I'm&cp1=1

    Has anyone had a chance to read that article?

    How does it affect cpanel users?

  2. #2
    Member
    Join Date
    Nov 2001
    Posts
    24

    Default

    I was just coming to ask the same thing A fairly big exploit by the sounds of it.

  3. #3
    Moderator cPanel Partner NOC Badge dgbaker's Avatar
    Join Date
    Sep 2002
    Location
    Toronto, Ontario Canada
    Posts
    2,773

    Default

    It's going into our servers now.

    This is from the RH Advisory System
    Red Hat Network has determined that the following advisory is applicable to one or more of the systems you have registered:


    Security Advisory - RHSA-2003:073-06
    ------------------------------------------------------------------------------
    Summary:
    Updated sendmail packages fix critical security issues
    Regards,
    David
    Forum Moderator

  4. #4
    Member
    Join Date
    Aug 2002
    Location
    Huntington Beach, Ca
    Posts
    232

    Default

    So what is the vote manual upgrade?

  5. #5
    Member
    Join Date
    Nov 2001
    Posts
    24

    Default

    Hmm, would be nice to see it packaged in a Cpanel update

  6. #6
    Member
    Join Date
    Jul 2002
    Posts
    214

    Default

    Will be then, an update on this?

    Cretu

  7. #7
    Member
    Join Date
    Aug 2001
    Posts
    421
    cPanel/Enkompass Access Level

    Root Administrator

    Default Re: sendmail vuln.

    Originally posted by s3kk3y
    http://www.msnbc.com/news/880094.asp?0cv=CB10I'm&cp1=1

    Has anyone had a chance to read that article?

    How does it affect cpanel users?
    cPanel uses Exim -- /usr/lib/sendmail and /usr/sbin/sendmail are actually symlinked to Exim.

  8. #8
    Member
    Join Date
    Jul 2002
    Posts
    214

    Default

    So, should I patch the sendmail with rmp from Red Hat or not?
    Sorry for my ignorence but I really seek clear answers.

    Cretu

  9. #9
    Member
    Join Date
    Aug 2002
    Location
    Huntington Beach, Ca
    Posts
    232

    Default

    "Since this is a message-based vulnerability, MTAs other than Sendmail may pass on the carefully crafted message. This means that unpatched versions of Sendmail inside a network could still be at risk even if they do not accept external connections directly."

    From RedHat Network

  10. #10
    Member rpmws's Avatar
    Join Date
    Aug 2001
    Location
    back woods of NC, USA
    Posts
    1,858

    Default

    I think I am seeing this now in my logs. I have 2 IPs hitting my mail server. Each one hits different times. about 200 hits and then it stops for 5 minutes. The IPs are RIPE IPs

    I don't think we can be infected or compromised but it is causing my mail server to bog down already
    Just keeping my "eye" on things....
    R. Paul Mathews
    RPMWS - diehard cPanel Nutcase

  11. #11
    Member
    Join Date
    Aug 2002
    Location
    Huntington Beach, Ca
    Posts
    232

    Default

    So since Exim is in use this exploit does not apply - correct?

  12. #12
    ozzi4648
    Guest

    Default

    Originally posted by rpmws
    I think I am seeing this now in my logs. I have 2 IPs hitting my mail server. Each one hits different times. about 200 hits and then it stops for 5 minutes. The IPs are RIPE IPs

    I don't think we can be infected or compromised but it is causing my mail server to bog down already
    Who me a snippet of those server hits. I want to see what your referring to.

  13. #13
    Member rpmws's Avatar
    Join Date
    Aug 2001
    Location
    back woods of NC, USA
    Posts
    1,858

    Default

    It's calmed down now ..but just today and yesterday over 100K of these below and 80K from the other IP. no other large mail issues. 30 in cue. No spam going out. I don't know maybe I am wrong.. but i have never seen this before.


    2003-03-03 14:53:41 18pw0K-000487-00 rejected from no-reverse.interalpha.net (ernst) [195.26.229.10]: can't currently verify any sender in the header lines (envelope sender is <newmanrt@columbus.rr.com>) - try later
    2003-03-03 14:53:50 18pw0S-00048z-00 rejected from no-reverse.interalpha.net (ernst) [195.26.229.10]: can't currently verify any sender in the header lines (envelope sender is <newmanrt@columbus.rr.com>) - try later
    2003-03-03 14:53:55 18pw0Y-00049t-00 rejected from no-reverse.interalpha.net (ernst) [195.26.229.10]: can't currently verify any sender in the header lines (envelope sender is <newmanrt@columbus.rr.com>) - try later
    2003-03-03 14:54:02 18pw0f-0004A3-00 rejected from no-reverse.interalpha.net (ernst) [195.26.229.10]: can't currently verify any sender in the header lines (envelope sender is <newmanrt@columbus.rr.com>) - try later
    2003-03-03 14:54:07 18pw0k-0004AQ-00 rejected from no-reverse.interalpha.net (ernst) [195.26.229.10]: can't currently verify any sender in the header lines (envelope sender is <newmanrt@columbus.rr.com>) - try later
    2003-03-03 14:54:14 18pw0r-0004B3-00 rejected from no-reverse.interalpha.net (ernst) [195.26.229.10]: can't currently verify any sender in the header lines (envelope sender is <newmanrt@columbus.rr.com>) - try later
    2003-03-03 14:54:20 18pw0x-0004BA-00 rejected from no-reverse.interalpha.net (ernst) [195.26.229.10]: can't currently verify any sender in the header lines (envelope sender is <newmanrt@columbus.rr.com>) - try later
    Last edited by rpmws; 03-04-2003 at 02:07 AM.
    Just keeping my "eye" on things....
    R. Paul Mathews
    RPMWS - diehard cPanel Nutcase

  14. #14
    ozzi4648
    Guest

    Default

    I dont know if you can call those the exploit hits but i can tell you that if i was you i would just plop those UK ips into my firewall for good.

  15. #15
    Member rpmws's Avatar
    Join Date
    Aug 2001
    Location
    back woods of NC, USA
    Posts
    1,858

    Default

    already did
    Just keeping my "eye" on things....
    R. Paul Mathews
    RPMWS - diehard cPanel Nutcase

Similar Threads & Tags
Similar threads

  1. Replies: 4
    Last Post: 02-01-2007, 03:21 PM
  2. Freebsd 5.4 vuln packages!
    By jackie46 in forum cPanel and WHM Discussions
    Replies: 7
    Last Post: 05-02-2006, 03:32 PM
  3. Pure-ftpd bologna vuln
    By lbccserv in forum cPanel and WHM Discussions
    Replies: 6
    Last Post: 08-12-2005, 05:40 AM
  4. Looking for file, mail/sendmail.mc and services/sendmail
    By demomen in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 06-08-2005, 03:22 AM
  5. A serious cpanel vuln?
    By moorer in forum cPanel and WHM Discussions
    Replies: 17
    Last Post: 01-28-2005, 01:30 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube