- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Verifying Sendmail Patch Level
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-18-2003 06:31 AM
08-18-2003 06:31 AM
Verifying Sendmail Patch Level
Is there a foolproof way to determine whether a version of Sendmail is fully patched? I'm fairly certain I applied the "manual updates" in March and April 2003 when several vulnerabilities were published, but how can I be sure? How can I convince the IS department around here that I am protected against various specific exploits? (Namely, remote buffer overflows, DNS handling overflow, smrsh error, "-bt overflow attack", local buffer overlow, etc...the list goes on).
I am running HP-UX 11.0 on a J5600 workstation. Telnetting to port 25 shows 8.11.1/8.11.1. The date of /usr/contrib/sendmail/usr/sbin/sendmail is April 4, 2003. Even if I were to download the July 2003 "special release" version from software.hp.com, how can I know for certain that the above vulnerabilities have been patched?
Thanks for any assistance,
Gus
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-18-2003 06:36 AM
08-18-2003 06:36 AM
Re: Verifying Sendmail Patch Level
It will show all patches.
To do more, you are going to have to download some hacking instructions(I will not post that stuff here) and demonstrate to your management/auditors that you can withstand attack.
You also might want to set up httpd and dns in a chroot jail where users other than root start and own the daemons.
The best way to keep up is to get itrc security updates, and watch here for posts by Berlene Herren, she posts the warnings for HP the minute they are ready.
SEP
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-18-2003 06:38 AM
08-18-2003 06:38 AM
Re: Verifying Sendmail Patch Level
There was some discussion after the initial announcement of the vulnerabilities and the associated fix about how to tell if your version was OK:
http://forums.itrc.hp.com/cm/QuestionAnswer/1,,0x5c669c196a4bd71190080090279cd0f9,00.html
Pete
Pete
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-18-2003 06:40 AM
08-18-2003 06:40 AM
Re: Verifying Sendmail Patch Level
Massimo
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-18-2003 07:51 AM
08-18-2003 07:51 AM
Re: Verifying Sendmail Patch Level
BTW, I don't see any of that "JAG" stuff when I run the "what ...sendmail" command, even though I just loaded the July 2003 special release. Here is what I get:
/etc/mail> what /usr/sbin/sendmail
/usr/sbin/sendmail:
Copyright (c) 1998 HEWLETT PACKARD COMPANY and its licensors,
including Sendmail, Inc., and the Regents of the
University of California. All rights reserved.
version.c 8.11.1 (Berkeley) - Revision 1.4 - 2003/05/05
I guess that maybe the JAG identifier (?) isn't included in all releases.
Gus
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-19-2003 11:17 AM
08-19-2003 11:17 AM
Re: Verifying Sendmail Patch Level
echo \$Z | /usr/sbin/sendmail -bt -d
Rgds...Geoff