[Esd-l] RE: Detection rule for sendmail header exploit

John D. Hardin jhardin at impsec.org
Mon Mar 10 19:42:13 PST 2003

On Mon, 10 Mar 2003, Mike Loiterman wrote:

> Actually, I was referring to your comment in one of the last
> digests.  This doesn't seem to be incorporated in the file from
> 3/5/03:
> > Another point to note is that the RE should begin with the
> > following in order to trap all headers for which sendmail is
> > vulnerable:
> > 
> > * ^((resent-)?(sender|from|(reply-)?to|cc|bcc)\
> >     |(errors|disposition-notification|apparently)-to):
> Thanks! I've incorporated that.
> Is this an additional part to the sendmail exploit rule, or is
> this for something else?

No, the sendmail exploit rule was altered to imcorporate the above RE.
The local-rules file on the website (NOT the example in the
documentation) includes these changes. I just verified that now. It's
dated 3/8/2003.

