From owner-freebsd-security Mon Nov 18 10:19:41 1996 Return-Path: owner-security Received: (from root@localhost) by freefall.freebsd.org (8.7.5/8.7.3) id KAA02437 for security-outgoing; Mon, 18 Nov 1996 10:19:41 -0800 (PST) Received: from alpha.xerox.com (alpha.Xerox.COM [13.1.64.93]) by freefall.freebsd.org (8.7.5/8.7.3) with SMTP id KAA02432 for ; Mon, 18 Nov 1996 10:19:37 -0800 (PST) Received: from crevenia.parc.xerox.com ([13.2.116.11]) by alpha.xerox.com with SMTP id <17626(1)>; Mon, 18 Nov 1996 10:18:46 PST Received: by crevenia.parc.xerox.com id <177557>; Mon, 18 Nov 1996 10:18:25 -0800 From: Bill Fenner To: fenner@parc.xerox.com, imp@village.org Subject: Re: BoS: Exploit for sendmail smtpd bug (ver. 8.7-8.8.2). Cc: freebsd-security@freebsd.org, msmith@atrad.adelaide.edu.au Message-Id: <96Nov18.101825pst.177557@crevenia.parc.xerox.com> Date: Mon, 18 Nov 1996 10:18:10 PST Sender: owner-security@freebsd.org X-Loop: FreeBSD.org Precedence: bulk >You then must give up running the shell scripts in the users' .forward >file as that user. mail.local doesn't do this, btw. Sorry, I forgot about this since Xerox doesn't allow .forward files at all. Bill