From owner-freebsd-hackers@FreeBSD.ORG Sun Aug 27 04:58:47 2006 Return-Path: X-Original-To: hackers@freebsd.org Delivered-To: freebsd-hackers@FreeBSD.ORG Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id AC9D416A4DD for ; Sun, 27 Aug 2006 04:58:47 +0000 (UTC) (envelope-from gshapiro@gshapiro.net) Received: from gir.gshapiro.net (gir.gshapiro.net [209.246.26.16]) by mx1.FreeBSD.org (Postfix) with ESMTP id 685A143D45 for ; Sun, 27 Aug 2006 04:58:47 +0000 (GMT) (envelope-from gshapiro@gshapiro.net) Received: from gir.gshapiro.net (localhost [127.0.0.1]) by gir.gshapiro.net (8.13.5/8.13.6) with ESMTP id k7R4wgql016481 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Sat, 26 Aug 2006 21:58:43 -0700 (PDT) (envelope-from gshapiro@gir.gshapiro.net) X-DKIM: Sendmail DKIM Filter v0.5.1 gir.gshapiro.net k7R4wgql016481 Received: (from gshapiro@localhost) by gir.gshapiro.net (8.13.5/8.13.6/Submit) id k7R4wgl9016480; Sat, 26 Aug 2006 21:58:42 -0700 (PDT) (envelope-from gshapiro) Date: Sat, 26 Aug 2006 21:58:42 -0700 From: Gregory Shapiro To: Mike Meyer Message-ID: <20060827045842.GA1032@gir.gshapiro.net> References: <44F0E38F.5030809@erdgeist.org> <17648.59470.572563.377998@bhuda.mired.org> <20060827052733.F16322@erdgeist.org> <17649.9146.307818.780974@bhuda.mired.org> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <17649.9146.307818.780974@bhuda.mired.org> User-Agent: Mutt/1.5.12-2006-07-14 Cc: hackers@freebsd.org, Dirk Engling Subject: Re: jails, cron and sendmail X-BeenThere: freebsd-hackers@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Technical Discussions relating to FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 27 Aug 2006 04:58:47 -0000 > The default configuration doesn't expose sendmail to the publicly > visible IP addres. The daemon it runs only listens for connections to > the localhost address. Unfortunately, in jails, localhost gets remapped to the jail IP address and therefore, he is correct, it is accepting connections from the outside world. This is one thing that I would love to see fixed in jails.