SMTP in debug mode

Risk Level: High risk vulnerability  High

Check or Attack Name: smtpdebug

Platforms: Sendmail: Old
Description:

Sendmail was found in debug mode. Debug mode allows an attacker to gain access to a machine through the sendmail port. This option looks for old versions of sendmail that allow debug mode and could provide an attacker access to the machine.

Remedy:

Obtain and install a more recent version of Sendmail, which does not implement the DEBUG feature.

References:

CERT Advisory CA-93.14, Internet Security Scanner (ISS), http://www.cert.org/advisories/CA-93.14.Internet.Security.Scanner.html

Sendmail Consortium, Sendmail Homepage, http://www.sendmail.org


X-Force Logo
Know Your Risks