Next | Classic Unix Security Problems | 27 |
Another vector for the Morris worm was sendmail
(Isn't it always?)
sendmail had a "debug" mode
You could connect to it and send it shell commands
It would execute these on the remote machine
Many vendors enabled this by default
continued...
Next | Copyright © 2005 M. J. Dominus |