Path: utzoo!attcan!utgpu!watmath!clyde!att!osu-cis!tut.cis.ohio-state.edu!mailrus!purdue!decwrl!vixie From: vixie@decwrl.dec.com (Paul Vixie) Newsgroups: news.sysadmin Subject: Re: virus & DEC... Message-ID: <894@bacchus.dec.com> Date: 12 Nov 88 11:25:44 GMT References: <3480@hubcap.UUCP> <183900001@uxc.cso.uiuc.edu> Organization: DEC Western Research Lab Lines: 18 ### [...] you have to throw away Ultrix sendmail and install BSD sendmail [...] ## ...fixed in 3.0. # # I hope it's fixed all the way. The 3.0 systems inside DEC had BOTH the # sendmail and fingerd bugs. I bet there were people scrambling Thursday... Not really. Someone caught it early and battoned down the hatches. We did not have the fingerd bug because our externally reachable machines run fingd which does a bounded read(2) rather than a gets(3). Our sendmail was the BSD 5.59 one with some local hacks and we got a few worms in that way. If we had been running the field test 3.0 sendmail, we would have been completely immune. (STILL not a company spokesman, btw.) -- Paul Vixie Work: vixie@decwrl.dec.com decwrl!vixie +1 415 853 6600 Play: paul@vixie.sf.ca.us vixie!paul +1 415 864 7013