Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
kag
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
3 ms
·
1.
▲
by
kag
12y ago
Of course bash doesn't know and shouldn't know about the SMTP RFCs. Yes, bash shouldn't execute code in variables. I was talking about input validation in qmail itself, not bash. Even though bash shouldn't have execute
2.
▲
by
kag
12y ago
Yeah, it does. I meant Debian, but it looks like Debian changed too. My bad. My point was that changing /bin/sh from the distro-chosen one to something else could cause problems.
3.
▲
by
kag
12y ago
>> 2. uninstall Bash and use a barebones POSIX-like shell without extra features. It's not that simple. True, djb doesn't say you need bash. But qmail uses /bin/sh (not configurable without recompiling). Try cha
4.
▲
by
kag
12y ago
Yes, this is not exploitable without vulnerable bash. But to paraphrase from the thread: However, qmail is not parsing mail from:<> and rcpt to:<> in accordance with RFC821/RFC2821. Almost anything is allowed between the &
5.
▲
Qmail is a vector for bash shellshock
(marc.info)
57 points
by
kag
12y ago
|
31 comments
6.
▲
by
kag
12y ago
Why it's not exploitable without the shellshock-vulnerable bash, you could argue that qmail is not validating the input in accordance with the RFCs. In fact, that's one of the things I said here: http://marc.info/