Mailing Lists: Apple Mailing Lists

Image of Mac OS face in stamp
 
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

questions about mail



My school district is really concerned about hacking and I guess is running a pretty extensive scan on all servers that are open to the internet. They got these errors.

The remote SMTP server did not complain when issued the command:
Mail From: root@this_hose
Receipt to : /tmp/nessus_test
This probably means that it is possible to send mail directly to files, which is a serious threat, since this allows anyone to overwrite any file on the remote server

And

The remote SMTP server did not complain when issued the command:
Mail From: root@this_hose
Receipt to : testing
This probably means that it is possible to send mail directly to programs, which is a serious threat, since this allows anyone to execute arbitrary commands on this host.

The solution give is to upgrade my MTA or change it.

Any help is appreciated.

Bill Crockett
_______________________________________________
macos-x-server mailing list | email@hidden
Help/Unsubscribe/Archives: http://www.lists.apple.com/mailman/listinfo/macos-x-server
Do not post admin requests to the list. They will be ignored.



Visit the Apple Store online or at retail locations.
1-800-MY-APPLE

Contact Apple | Terms of Use | Privacy Policy

Copyright © 2007 Apple Inc. All rights reserved.