As far as software goes, Sendmail is ancient, dating all the way back to 1981. Sendmail 8 itself is well over 10 years-old. To put it nicely, its security track record is less than stellar. However, the last big show stoppers in Sendmail were found about three years ago – Zalewski's prescan() bugs reported in September and March of 2003, and crackaddr(), also in March of 2003. The crackaddr() bug was also discovered by Mark Dowd. . The link for this article located at TheRegister.co.uk is no longer available. . Sendmail, once a leader in email transfer, now faces significant vulnerabilities and inefficiencies due to its outdated architecture and antiquated design practices. Sendmail Software, Email Security, Protocol Flaws, Security Issues. . LinuxSecurity.com Team
The protocol that has defined e-mail for more than two decades may have a fatal flaw: It trusts you. Developed when the Internet was used almost exclusively by academics, the Simple Mail Transfer Protocol, or SMTP, assumes that you are . . . . The protocol that has defined e-mail for more than two decades may have a fatal flaw: It trusts you. Developed when the Internet was used almost exclusively by academics, the Simple Mail Transfer Protocol, or SMTP, assumes that you are who you say you are. SMTP makes that assumption because it doesn't suspect that you're sending a Trojan horse virus or fraudulent pleas for money from the relations of deposed African dictators, or that you've hijacked somebody else's computer to send tens of millions of advertisements for herbal Viagra. In other words, SMTP trusts too much--and that has spam foes, security mavens and even an original architect of today's e-mail system agitating for an overhaul, if not an outright replacement, of the omnipresent protocol. "I would suggest they just write a new protocol from the beginning," said Suzanne Sluizer, a co-author of SMTP's immediate predecessor and a visiting lecturer at the University of New Mexico, in an interview. . The foundation that has governed online messaging for over twenty years could possess a critical vulnerability: It relies on trust.. Email Protocol, SMTP Security, Protocol Risks. . LinuxSecurity.com Team
Several users welcomed the growing willingness of vendors and security researchers to work together to identify and fix software vulnerabilities in the wake of last week's disclosure of a major hole in a widely used e-mail protocol .. . .. Several users welcomed the growing willingness of vendors and security researchers to work together to identify and fix software vulnerabilities in the wake of last week's disclosure of a major hole in a widely used e-mail protocol . But they also expressed concern over the practice by some in the security community to release vulnerability information to certain users before making it available to the public. Atlanta-based security vendor Internet Security Systems Inc. (ISS) and Emeryville, Calif.-based Sendmail Inc. last week disclosed the existence of a major buffer-overflow vulnerability in the sendmail mail-transfer agent, which handles more than 50% of all Internet e-mail traffic. The link for this article located at Computerworld is no longer available. . Numerous individuals recognized the growing partnership among suppliers and security experts to address weaknesses.. Software Vulnerabilities,Bug Disclosure,Incident Response,Security Collaboration. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.