<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sendmail 8.9.3 and Security in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/sendmail-8-9-3-and-security/m-p/2746238#M68965</link>
    <description>Hi&lt;BR /&gt;&lt;BR /&gt;Try this :-&lt;BR /&gt;&lt;BR /&gt;Telnet to your server using port 25,&lt;BR /&gt;&lt;BR /&gt;it will return somthing like this :-Trying...                                                                       &lt;BR /&gt;Connected to &lt;BR /&gt;&lt;IP address=""&gt;.&lt;BR /&gt;                                &lt;BR /&gt;Escape character is '^]'.                                                       &lt;BR /&gt;220 d370 ESMTP Sendmail 8.8.6 (PHNE_17190)/8.8.6; Mon, 17 Jun 2002 18:52:49 -060&lt;BR /&gt;0 (MDT)                                                                         &lt;BR /&gt;Hostname is there :- "d370"&lt;BR /&gt;&lt;BR /&gt;Sendmail version :-8.8.6 &lt;BR /&gt;&lt;BR /&gt;The PHNE indicated a Unix server&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Try:- &lt;BR /&gt;&lt;BR /&gt;vrfy root&lt;BR /&gt; 250 Super User &lt;ROOT&gt;&lt;BR /&gt;&lt;BR /&gt;vrfy fred&lt;BR /&gt;&lt;BR /&gt;550 fred unknown user.&lt;BR /&gt;&lt;BR /&gt;vrfy bert&lt;BR /&gt;&lt;BR /&gt;250 Super User &lt;ROOT&gt;&lt;BR /&gt;&lt;BR /&gt;------------------------------------------&lt;BR /&gt;&lt;BR /&gt;Right, what have we got without logging into the server.&lt;BR /&gt;&lt;BR /&gt;IT is a HP-UX machine running sendmail version 8.8.6 it does not have a user called fred in the passwd file but has a user called bert who has superuser rights.&lt;BR /&gt;&lt;BR /&gt;So Bert looks like a good way in:-&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;HTH&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;BTW the HP security course is one of the fun ones !!!&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Paula&lt;BR /&gt;&lt;BR /&gt;&lt;/ROOT&gt;&lt;/ROOT&gt;&lt;/IP&gt;</description>
    <pubDate>Mon, 17 Jun 2002 17:02:21 GMT</pubDate>
    <dc:creator>Paula J Frazer-Campbell</dc:creator>
    <dc:date>2002-06-17T17:02:21Z</dc:date>
    <item>
      <title>Sendmail 8.9.3 and Security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/sendmail-8-9-3-and-security/m-p/2746236#M68963</link>
      <description>My corporate IS department has suggested we move to 8.9.3 (latest?) in order to use its mail server relay capabilities for security reasons.  I currently have version 8.8.6.1 and have installed the latest patch software that I have (3/2002).&lt;BR /&gt;&lt;BR /&gt;I can't seem to find the patch, where would I find this patch/upgrade?  Is it Patch: PHNE_24419 or PHNE_17190 or something else?&lt;BR /&gt;&lt;BR /&gt;Is it truly that easy to hack into a system using port 25 of sendmail?  I can't seem to do it, but then again I've never tried to hack into it before, so I may not be doing everything "correctly".&lt;BR /&gt;&lt;BR /&gt;Any thoughts or experiences are appreciated.&lt;BR /&gt;</description>
      <pubDate>Mon, 17 Jun 2002 15:43:43 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/sendmail-8-9-3-and-security/m-p/2746236#M68963</guid>
      <dc:creator>Tracey</dc:creator>
      <dc:date>2002-06-17T15:43:43Z</dc:date>
    </item>
    <item>
      <title>Re: Sendmail 8.9.3 and Security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/sendmail-8-9-3-and-security/m-p/2746237#M68964</link>
      <description>PHNE_24419 is for 11.0&lt;BR /&gt;&lt;BR /&gt;try this url:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://support1.itrc.hp.com/service/patch/patchDetail.do?patchid=PHNE_24419&amp;amp;context=hpux:800:11:00" target="_blank"&gt;http://support1.itrc.hp.com/service/patch/patchDetail.do?patchid=PHNE_24419&amp;amp;context=hpux:800:11:00&lt;/A&gt;</description>
      <pubDate>Mon, 17 Jun 2002 16:40:05 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/sendmail-8-9-3-and-security/m-p/2746237#M68964</guid>
      <dc:creator>Bill Costigan</dc:creator>
      <dc:date>2002-06-17T16:40:05Z</dc:date>
    </item>
    <item>
      <title>Re: Sendmail 8.9.3 and Security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/sendmail-8-9-3-and-security/m-p/2746238#M68965</link>
      <description>Hi&lt;BR /&gt;&lt;BR /&gt;Try this :-&lt;BR /&gt;&lt;BR /&gt;Telnet to your server using port 25,&lt;BR /&gt;&lt;BR /&gt;it will return somthing like this :-Trying...                                                                       &lt;BR /&gt;Connected to &lt;BR /&gt;&lt;IP address=""&gt;.&lt;BR /&gt;                                &lt;BR /&gt;Escape character is '^]'.                                                       &lt;BR /&gt;220 d370 ESMTP Sendmail 8.8.6 (PHNE_17190)/8.8.6; Mon, 17 Jun 2002 18:52:49 -060&lt;BR /&gt;0 (MDT)                                                                         &lt;BR /&gt;Hostname is there :- "d370"&lt;BR /&gt;&lt;BR /&gt;Sendmail version :-8.8.6 &lt;BR /&gt;&lt;BR /&gt;The PHNE indicated a Unix server&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Try:- &lt;BR /&gt;&lt;BR /&gt;vrfy root&lt;BR /&gt; 250 Super User &lt;ROOT&gt;&lt;BR /&gt;&lt;BR /&gt;vrfy fred&lt;BR /&gt;&lt;BR /&gt;550 fred unknown user.&lt;BR /&gt;&lt;BR /&gt;vrfy bert&lt;BR /&gt;&lt;BR /&gt;250 Super User &lt;ROOT&gt;&lt;BR /&gt;&lt;BR /&gt;------------------------------------------&lt;BR /&gt;&lt;BR /&gt;Right, what have we got without logging into the server.&lt;BR /&gt;&lt;BR /&gt;IT is a HP-UX machine running sendmail version 8.8.6 it does not have a user called fred in the passwd file but has a user called bert who has superuser rights.&lt;BR /&gt;&lt;BR /&gt;So Bert looks like a good way in:-&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;HTH&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;BTW the HP security course is one of the fun ones !!!&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Paula&lt;BR /&gt;&lt;BR /&gt;&lt;/ROOT&gt;&lt;/ROOT&gt;&lt;/IP&gt;</description>
      <pubDate>Mon, 17 Jun 2002 17:02:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/sendmail-8-9-3-and-security/m-p/2746238#M68965</guid>
      <dc:creator>Paula J Frazer-Campbell</dc:creator>
      <dc:date>2002-06-17T17:02:21Z</dc:date>
    </item>
    <item>
      <title>Re: Sendmail 8.9.3 and Security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/sendmail-8-9-3-and-security/m-p/2746239#M68966</link>
      <description>Hi&lt;BR /&gt;&lt;BR /&gt;Btw&lt;BR /&gt;&lt;BR /&gt;To disable vrfy edit:-&lt;BR /&gt;&lt;BR /&gt;/etc/mail/sendmail.cf&lt;BR /&gt;find PrivacyOptions test&lt;BR /&gt;add line "O PrivacyOptions=novrfy"&lt;BR /&gt;stop and restart send mail:-&lt;BR /&gt;&lt;BR /&gt;/sbin/init.d/sendmail stop/start&lt;BR /&gt;&lt;BR /&gt;and recheck the vrvf command.&lt;BR /&gt;It wiil now not work.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Paula</description>
      <pubDate>Mon, 17 Jun 2002 17:05:43 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/sendmail-8-9-3-and-security/m-p/2746239#M68966</guid>
      <dc:creator>Paula J Frazer-Campbell</dc:creator>
      <dc:date>2002-06-17T17:05:43Z</dc:date>
    </item>
    <item>
      <title>Re: Sendmail 8.9.3 and Security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/sendmail-8-9-3-and-security/m-p/2746240#M68967</link>
      <description>Thanks,&lt;BR /&gt;&lt;BR /&gt;I've turned off the verify, and there was also an interesting little privacy option of "goaway".  Now that I understand how to get in, and I have set the two privacy options, I can still type:&lt;BR /&gt;&lt;BR /&gt;MAIL From:&lt;ROOT&gt;&lt;BR /&gt;&lt;BR /&gt;and it tells me "Sender OK"  which I am lead to beleive will allow others to send bogus email from my system - is there any way of stopping this - short of shutting down sendmail?&lt;/ROOT&gt;</description>
      <pubDate>Mon, 17 Jun 2002 17:34:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/sendmail-8-9-3-and-security/m-p/2746240#M68967</guid>
      <dc:creator>Tracey</dc:creator>
      <dc:date>2002-06-17T17:34:21Z</dc:date>
    </item>
    <item>
      <title>Re: Sendmail 8.9.3 and Security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/sendmail-8-9-3-and-security/m-p/2746241#M68968</link>
      <description>It would be tough to filter good and bad email. If you have the latest 8.9.3 to block relays and have changed your PrivacyOptions, then you have done what I would recommend. The only thing I would add that could lock down port 25 more is IPF/9000. You can write filtering rules to determine if the source is an ip you want to receive mail from or not.&lt;BR /&gt;&lt;BR /&gt;GL,&lt;BR /&gt;C</description>
      <pubDate>Mon, 17 Jun 2002 17:51:05 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/sendmail-8-9-3-and-security/m-p/2746241#M68968</guid>
      <dc:creator>Craig Rants</dc:creator>
      <dc:date>2002-06-17T17:51:05Z</dc:date>
    </item>
    <item>
      <title>Re: Sendmail 8.9.3 and Security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/sendmail-8-9-3-and-security/m-p/2746242#M68969</link>
      <description>For information, &lt;BR /&gt;Sendmail latest is 8.12.3, and this version include many securities (relay and so on....).&lt;BR /&gt;Of course, you don't have the latest version on HP's cd, you have to download from sendmail.org and compile by hand to make it work.&lt;BR /&gt;It's true that between 8.8 and 8.9, security is better (for the 8.9), because by default some capabilities like relay are closed.  You have to open it to make it work.&lt;BR /&gt;&lt;BR /&gt;Hope it'll help</description>
      <pubDate>Tue, 18 Jun 2002 06:39:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/sendmail-8-9-3-and-security/m-p/2746242#M68969</guid>
      <dc:creator>benoit Bruckert</dc:creator>
      <dc:date>2002-06-18T06:39:02Z</dc:date>
    </item>
  </channel>
</rss>

