<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Linux admin's What are you doing about the latest sendmail security problem in Operating System - Linux</title>
    <link>https://community.hpe.com/t5/operating-system-linux/linux-admin-s-what-are-you-doing-about-the-latest-sendmail/m-p/3761038#M86063</link>
    <description>Interesting,&lt;BR /&gt;&lt;BR /&gt;There is nothing in the changelog (Thanks Vitaly 10 points to you) mentioning the recent security issue.&lt;BR /&gt;&lt;BR /&gt;I must conclude that there is mroe to do. Where is the security patch from sendmail to add on?&lt;BR /&gt;&lt;BR /&gt;SEP</description>
    <pubDate>Thu, 30 Mar 2006 02:15:04 GMT</pubDate>
    <dc:creator>Steven E. Protter</dc:creator>
    <dc:date>2006-03-30T02:15:04Z</dc:date>
    <item>
      <title>Linux admin's What are you doing about the latest sendmail security problem</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-admin-s-what-are-you-doing-about-the-latest-sendmail/m-p/3761026#M86051</link>
      <description>Sendmail race condition issue&lt;BR /&gt;&lt;BR /&gt;CERT has reported a race condition issue in sendmail which may lead to&lt;BR /&gt;arbitrary remote code execution.&lt;BR /&gt;&lt;BR /&gt;CERT has assinged this issue the name VU#834865&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;This issue also affects RHEL3&lt;BR /&gt;This issue also affects RHEL2.1&lt;BR /&gt;&lt;BR /&gt;To quote CERT regarding this patch:&lt;BR /&gt;&lt;BR /&gt;    A patch to correct this issue in sendmail versions 8.13 is provided&lt;BR /&gt;    below. The patch also eliminates potential integer overflows in how&lt;BR /&gt;    sendmail handles message headers. This patch was prepared manually by&lt;BR /&gt;    Sendmail and in our experience will generate warnings about&lt;BR /&gt;    offsets. We've discussed this with Sendmail and believe it to be&lt;BR /&gt;    harmless. Aside from that, CERT/CC has not verified this patch, what&lt;BR /&gt;    issues are corrected, and how those issues are corrected.&lt;BR /&gt;&lt;BR /&gt;I have a mail gateway server RH AS 2.1 at risk.&lt;BR /&gt;&lt;BR /&gt;RH seems to say upgrade to their sendmail 8.12 and then apply a patch at sendmail.org.&lt;BR /&gt;&lt;BR /&gt;I'm having trouble finding the patch and would like to know what upgrade procedure people are using.&lt;BR /&gt;&lt;BR /&gt;I'd really rather just install a 8.13.x rpm but RH does not seem to provide such a thing.&lt;BR /&gt;&lt;BR /&gt;SEP&lt;BR /&gt;&lt;BR /&gt;I find RH's notice confusing.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 29 Mar 2006 02:59:27 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-admin-s-what-are-you-doing-about-the-latest-sendmail/m-p/3761026#M86051</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2006-03-29T02:59:27Z</dc:date>
    </item>
    <item>
      <title>Re: Linux admin's What are you doing about the latest sendmail security problem</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-admin-s-what-are-you-doing-about-the-latest-sendmail/m-p/3761027#M86052</link>
      <description>sendmail-8.12.11-4.21AS.8.src.rpm&lt;BR /&gt;&lt;BR /&gt;This SRC file already has this patch applied to it.&lt;BR /&gt;&lt;BR /&gt;You may just need to download it and compile it yourself.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="ftp://ftp.redhat.com/pub/redhat/linux/enterprise/2.1AS/en/os/SRPMS/sendmail-8.12.11-4.21AS.8.src.rpm" target="_blank"&gt;ftp://ftp.redhat.com/pub/redhat/linux/enterprise/2.1AS/en/os/SRPMS/sendmail-8.12.11-4.21AS.8.src.rpm&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 29 Mar 2006 04:30:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-admin-s-what-are-you-doing-about-the-latest-sendmail/m-p/3761027#M86052</guid>
      <dc:creator>Stuart Browne</dc:creator>
      <dc:date>2006-03-29T04:30:20Z</dc:date>
    </item>
    <item>
      <title>Re: Linux admin's What are you doing about the latest sendmail security problem</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-admin-s-what-are-you-doing-about-the-latest-sendmail/m-p/3761028#M86053</link>
      <description>'n heh.. no fair.. I was most of the way through writing nice instructions on how to modify the spec file to do it all fo ryou.. I go to do the build, and the patch doesn't apply!... already in there.. *sigh* ah well :)</description>
      <pubDate>Wed, 29 Mar 2006 04:41:32 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-admin-s-what-are-you-doing-about-the-latest-sendmail/m-p/3761028#M86053</guid>
      <dc:creator>Stuart Browne</dc:creator>
      <dc:date>2006-03-29T04:41:32Z</dc:date>
    </item>
    <item>
      <title>Re: Linux admin's What are you doing about the latest sendmail security problem</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-admin-s-what-are-you-doing-about-the-latest-sendmail/m-p/3761029#M86054</link>
      <description>G'day Stuart,&lt;BR /&gt;&lt;BR /&gt;It would appear we can just install the binary rpm file. I've downloaded it and have initiated our internal change management process in order to come up with a schedule.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Wed, 29 Mar 2006 05:54:46 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-admin-s-what-are-you-doing-about-the-latest-sendmail/m-p/3761029#M86054</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2006-03-29T05:54:46Z</dc:date>
    </item>
    <item>
      <title>Re: Linux admin's What are you doing about the latest sendmail security problem</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-admin-s-what-are-you-doing-about-the-latest-sendmail/m-p/3761030#M86055</link>
      <description>Steven, because you have RHN subscription, you can download *binary* sendmail RPM from RH.&lt;BR /&gt;According to RHSA-2006:0265-01 (&lt;A href="https://www.redhat.com/archives/enterprise-watch-list/2006-March/msg00017.html)," target="_blank"&gt;https://www.redhat.com/archives/enterprise-watch-list/2006-March/msg00017.html),&lt;/A&gt; sendmail-8.12.11-4.21AS.8.i386.rpm contains the latest Sendmail path.</description>
      <pubDate>Wed, 29 Mar 2006 05:56:31 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-admin-s-what-are-you-doing-about-the-latest-sendmail/m-p/3761030#M86055</guid>
      <dc:creator>Vitaly Karasik_1</dc:creator>
      <dc:date>2006-03-29T05:56:31Z</dc:date>
    </item>
    <item>
      <title>Re: Linux admin's What are you doing about the latest sendmail security problem</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-admin-s-what-are-you-doing-about-the-latest-sendmail/m-p/3761031#M86056</link>
      <description>Ahh, good news.  (I don't have a RHE subscription handy here, so couldn't check).&lt;BR /&gt;&lt;BR /&gt;Certainly makes life easier.</description>
      <pubDate>Wed, 29 Mar 2006 06:05:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-admin-s-what-are-you-doing-about-the-latest-sendmail/m-p/3761031#M86056</guid>
      <dc:creator>Stuart Browne</dc:creator>
      <dc:date>2006-03-29T06:05:33Z</dc:date>
    </item>
    <item>
      <title>Re: Linux admin's What are you doing about the latest sendmail security problem</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-admin-s-what-are-you-doing-about-the-latest-sendmail/m-p/3761032#M86057</link>
      <description>Remember that CentOS provides the same packages that Enterprise:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://rpm.pbone.net/index.php3?stat=26&amp;amp;dist=43&amp;amp;size=528888&amp;amp;name=sendmail-8.12.11-4.21AS.8.i386.rpm" target="_blank"&gt;http://rpm.pbone.net/index.php3?stat=26&amp;amp;dist=43&amp;amp;size=528888&amp;amp;name=sendmail-8.12.11-4.21AS.8.i386.rpm&lt;/A&gt;</description>
      <pubDate>Wed, 29 Mar 2006 08:10:54 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-admin-s-what-are-you-doing-about-the-latest-sendmail/m-p/3761032#M86057</guid>
      <dc:creator>Ivan Ferreira</dc:creator>
      <dc:date>2006-03-29T08:10:54Z</dc:date>
    </item>
    <item>
      <title>Re: Linux admin's What are you doing about the latest sendmail security problem</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-admin-s-what-are-you-doing-about-the-latest-sendmail/m-p/3761033#M86058</link>
      <description>Thanks to all. Change Management request is in. Any symptons to worry about? Post em.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Wed, 29 Mar 2006 08:49:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-admin-s-what-are-you-doing-about-the-latest-sendmail/m-p/3761033#M86058</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2006-03-29T08:49:28Z</dc:date>
    </item>
    <item>
      <title>Re: Linux admin's What are you doing about the latest sendmail security problem</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-admin-s-what-are-you-doing-about-the-latest-sendmail/m-p/3761034#M86059</link>
      <description>I don't expect any problems, but reading Changelog will be a good idea. IIRC, "rpm --changelog packagename" will provide it.</description>
      <pubDate>Wed, 29 Mar 2006 11:50:10 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-admin-s-what-are-you-doing-about-the-latest-sendmail/m-p/3761034#M86059</guid>
      <dc:creator>Vitaly Karasik_1</dc:creator>
      <dc:date>2006-03-29T11:50:10Z</dc:date>
    </item>
    <item>
      <title>Re: Linux admin's What are you doing about the latest sendmail security problem</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-admin-s-what-are-you-doing-about-the-latest-sendmail/m-p/3761035#M86060</link>
      <description>Thank You Vitaly.&lt;BR /&gt;&lt;BR /&gt;Readers will probably benefit from knowing that Vitaly built the servers in question.&lt;BR /&gt;&lt;BR /&gt;:-)&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Wed, 29 Mar 2006 13:54:59 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-admin-s-what-are-you-doing-about-the-latest-sendmail/m-p/3761035#M86060</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2006-03-29T13:54:59Z</dc:date>
    </item>
    <item>
      <title>Re: Linux admin's What are you doing about the latest sendmail security problem</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-admin-s-what-are-you-doing-about-the-latest-sendmail/m-p/3761036#M86061</link>
      <description>That'd be 'rpm -q --changelog &lt;PACKAGENAME&gt;'..&lt;/PACKAGENAME&gt;</description>
      <pubDate>Wed, 29 Mar 2006 15:13:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-admin-s-what-are-you-doing-about-the-latest-sendmail/m-p/3761036#M86061</guid>
      <dc:creator>Stuart Browne</dc:creator>
      <dc:date>2006-03-29T15:13:36Z</dc:date>
    </item>
    <item>
      <title>Re: Linux admin's What are you doing about the latest sendmail security problem</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-admin-s-what-are-you-doing-about-the-latest-sendmail/m-p/3761037#M86062</link>
      <description>from the security alert from RH:&lt;BR /&gt;&lt;BR /&gt;In order to correct this issue for Red Hat Enterprise Linux 2.1 users, it&lt;BR /&gt;was necessary to upgrade the version of Sendmail from 8.11 as originally&lt;BR /&gt;shipped to Sendmail 8.12 with the addition of the security patch supplied&lt;BR /&gt;by Sendmail Inc.  This erratum provides updated packages based on Sendmail&lt;BR /&gt;8.12 with a compatibility mode enabled.  After updating to these packages,&lt;BR /&gt;users should pay close attention to their sendmail logs to ensure that the&lt;BR /&gt;upgrade completed sucessfully.&lt;BR /&gt;&lt;BR /&gt;Just install the RPM, it is a version increase which includes the fix. the only thing left for you to do is check if it still _runs as it should_ afterwards.</description>
      <pubDate>Thu, 30 Mar 2006 02:11:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-admin-s-what-are-you-doing-about-the-latest-sendmail/m-p/3761037#M86062</guid>
      <dc:creator>dirk dierickx</dc:creator>
      <dc:date>2006-03-30T02:11:03Z</dc:date>
    </item>
    <item>
      <title>Re: Linux admin's What are you doing about the latest sendmail security problem</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-admin-s-what-are-you-doing-about-the-latest-sendmail/m-p/3761038#M86063</link>
      <description>Interesting,&lt;BR /&gt;&lt;BR /&gt;There is nothing in the changelog (Thanks Vitaly 10 points to you) mentioning the recent security issue.&lt;BR /&gt;&lt;BR /&gt;I must conclude that there is mroe to do. Where is the security patch from sendmail to add on?&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Thu, 30 Mar 2006 02:15:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-admin-s-what-are-you-doing-about-the-latest-sendmail/m-p/3761038#M86063</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2006-03-30T02:15:04Z</dc:date>
    </item>
    <item>
      <title>Re: Linux admin's What are you doing about the latest sendmail security problem</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-admin-s-what-are-you-doing-about-the-latest-sendmail/m-p/3761039#M86064</link>
      <description>Steven,&lt;BR /&gt;security patch is already in: &lt;BR /&gt;&lt;BR /&gt;"This erratum provides updated packages based on Sendmail &lt;BR /&gt;8.12"&lt;BR /&gt;&lt;A href="https://rhn.redhat.com/errata/RHSA-2006-0265.html" target="_blank"&gt;https://rhn.redhat.com/errata/RHSA-2006-0265.html&lt;/A&gt;</description>
      <pubDate>Thu, 30 Mar 2006 03:55:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-admin-s-what-are-you-doing-about-the-latest-sendmail/m-p/3761039#M86064</guid>
      <dc:creator>Vitaly Karasik_1</dc:creator>
      <dc:date>2006-03-30T03:55:52Z</dc:date>
    </item>
    <item>
      <title>Re: Linux admin's What are you doing about the latest sendmail security problem</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-admin-s-what-are-you-doing-about-the-latest-sendmail/m-p/3761040#M86065</link>
      <description>Update,&lt;BR /&gt;&lt;BR /&gt;On the first server, the update went very well. Mail was being processed nicely before and after. Had to throw out the /etc/init.d/sendmail file because we had customization to permit our virus checker to listen on port 25 and then pass cleaned messages along to sendmail.&lt;BR /&gt;&lt;BR /&gt;Second server, which has been periodically overloaded with sendmail processes began to function very poorly after the upgrade and restart of mail services.&lt;BR /&gt;&lt;BR /&gt;The system became so overloaded during sendmail spikes it could scarecly do anything else.&lt;BR /&gt;&lt;BR /&gt;Had to add the following macros:&lt;BR /&gt;&lt;BR /&gt;define(`confCONNECT_RATE_THROTTLE', `100')dnl&lt;BR /&gt;dnl # Accept certain number of sendmail children&lt;BR /&gt;define(`confMAX_DAEMON_CHILDREN', `24')dnl&lt;BR /&gt;&lt;BR /&gt;The system isn't processing much mail, but other critical services it provides are at least working.&lt;BR /&gt;&lt;BR /&gt;The obvious conclusion is that this update fixes security issues, but it may not be as efficient in resource use, leading to a lower tolerance for simultaneous sendmail processes.&lt;BR /&gt;&lt;BR /&gt;I'm going to study the sendmail macros and look for a parameter that limits the number of connections from a single ip address, because it appears a DOS type attack is underway.&lt;BR /&gt;&lt;BR /&gt;Any clues on this could lead to more bountiful bunnies for those that provide the answer.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Thu, 30 Mar 2006 08:12:08 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-admin-s-what-are-you-doing-about-the-latest-sendmail/m-p/3761040#M86065</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2006-03-30T08:12:08Z</dc:date>
    </item>
    <item>
      <title>Re: Linux admin's What are you doing about the latest sendmail security problem</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-admin-s-what-are-you-doing-about-the-latest-sendmail/m-p/3761041#M86066</link>
      <description>How many sendmail processes did you see when second server was overloaded?&lt;BR /&gt;Did you really see tons of  SMTP connections from the same domain/address?&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 30 Mar 2006 11:22:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-admin-s-what-are-you-doing-about-the-latest-sendmail/m-p/3761041#M86066</guid>
      <dc:creator>Vitaly Karasik_1</dc:creator>
      <dc:date>2006-03-30T11:22:04Z</dc:date>
    </item>
    <item>
      <title>Re: Linux admin's What are you doing about the latest sendmail security problem</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-admin-s-what-are-you-doing-about-the-latest-sendmail/m-p/3761042#M86067</link>
      <description>Shalom Vitaly,&lt;BR /&gt;&lt;BR /&gt;After I throttled the connections, most of the connections were from other servers on the global network. As the primaries became unable to handle the load, the cost 200 servers began to pick up and process mail. You can see the MX record to see what I mean.&lt;BR /&gt;&lt;BR /&gt;Connection throttle and some subtle changes to the sendmail.mc configuration have the situaion under control. I lifted the connection throttle a few hours ago and am monitoring.&lt;BR /&gt;&lt;BR /&gt;Sendmail is a subtle creature, especially when you start using macros and can easily impact a global mail system.&lt;BR /&gt;&lt;BR /&gt;Kol Beseder, Baruch Hashem. Kol Yomim, ani lomed dvarim chadashim.&lt;BR /&gt;&lt;BR /&gt;We're looking into limit the number of simultaneous connections for non-nds sites to these servers. Maybe some firewall traffic shaping will help.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Thu, 30 Mar 2006 13:06:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-admin-s-what-are-you-doing-about-the-latest-sendmail/m-p/3761042#M86067</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2006-03-30T13:06:20Z</dc:date>
    </item>
    <item>
      <title>Re: Linux admin's What are you doing about the latest sendmail security problem</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-admin-s-what-are-you-doing-about-the-latest-sendmail/m-p/3761043#M86068</link>
      <description>We use 3 servers with the same-priority MX level, with :&lt;BR /&gt;&lt;BR /&gt;define(`confCONNECTION_RATE_THROTTLE', `10')dnl&lt;BR /&gt;define(`confMAX_DAEMON_CHILDREN', `1000')dnl&lt;BR /&gt;&lt;BR /&gt;They handle without issue up to about 40,000+/hour without batting an eyelid.&lt;BR /&gt;&lt;BR /&gt;These servers do virus scanning via clamav_milter, as well as two other custom milters (written in C).&lt;BR /&gt;&lt;BR /&gt;What sort of volume are your's seeing?</description>
      <pubDate>Thu, 30 Mar 2006 18:19:54 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-admin-s-what-are-you-doing-about-the-latest-sendmail/m-p/3761043#M86068</guid>
      <dc:creator>Stuart Browne</dc:creator>
      <dc:date>2006-03-30T18:19:54Z</dc:date>
    </item>
    <item>
      <title>Re: Linux admin's What are you doing about the latest sendmail security problem</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-admin-s-what-are-you-doing-about-the-latest-sendmail/m-p/3761044#M86069</link>
      <description>I'd have to run stats to answer your question Stuart,&lt;BR /&gt;&lt;BR /&gt;Volume is pretty high though.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Thu, 30 Mar 2006 19:22:30 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-admin-s-what-are-you-doing-about-the-latest-sendmail/m-p/3761044#M86069</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2006-03-30T19:22:30Z</dc:date>
    </item>
    <item>
      <title>Re: Linux admin's What are you doing about the latest sendmail security problem</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-admin-s-what-are-you-doing-about-the-latest-sendmail/m-p/3761045#M86070</link>
      <description>mailstats is your friend :)&lt;BR /&gt;&lt;BR /&gt;But not that friendly.&lt;BR /&gt;&lt;BR /&gt;mailstats + magic + mrtg :P</description>
      <pubDate>Thu, 30 Mar 2006 21:15:54 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-admin-s-what-are-you-doing-about-the-latest-sendmail/m-p/3761045#M86070</guid>
      <dc:creator>Stuart Browne</dc:creator>
      <dc:date>2006-03-30T21:15:54Z</dc:date>
    </item>
  </channel>
</rss>

