SMTP in debug mode |
---|
Risk Level: | High | Check or Attack Name: smtpdebug |
---|---|---|
Platforms: | Sendmail: Old | |
Description: | Sendmail was found in debug mode. Debug mode allows an attacker to gain access to a machine through the sendmail port. This option looks for old versions of sendmail that allow debug mode and could provide an attacker access to the machine. |
|
Remedy: | Obtain and install a more recent version of Sendmail, which does not implement the DEBUG feature. |
|
References: | CERT Advisory CA-93.14, Internet Security Scanner (ISS), http://www.cert.org/advisories/CA-93.14.Internet.Security.Scanner.html Sendmail Consortium, Sendmail Homepage, http://www.sendmail.org |
Know Your Risks |