[Esa-l] ANN: Procmail Sanitizer 1.140 released

John D. Hardin jhardin at impsec.org
Thu Feb 12 06:23:37 PST 2004


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


The procmail sanitizer has been updated. The current version is 1.140
It is available via:

US/WA:  http://www.impsec.org/email-tools/procmail-security.html
US/WA:  http://eucleides.com/sanitizer/procmail-security.html
EU/NL:  http://kanon.net/~jhardin/email-tools/procmail-security.html
#EU/NO:  http://oftedal.no/~jhardin/email-tools/procmail-security.html
AU:     http://grebopple.accessunited.com.au/email-tools/procmail-security.html
AU:     http://impsec.fuzzitech.net/email-tools/procmail-security.html

Direct links to the current tarball:

US/WA:  http://www.impsec.org/email-tools/procmail-sanitizer.tar.gz
US/WA:  http://eucleides.com/sanitizer/procmail-sanitizer.tar.gz
EU/NL:  http://kanon.net/~jhardin/email-tools/procmail-sanitizer.tar.gz
#EU/NO:  http://oftedal.no/~jhardin/email-tools/procmail-sanitizer.tar.gz
AU:     http://grebopple.accessunited.com.au/email-tools/procmail-sanitizer.tar.gz
AU:     http://impsec.fuzzitech.net/email-tools/procmail-sanitizer.tar.gz

("commented out" mirrors are temporarily out-of-sync or unavailable)


2ca7555f0e3375e8cd352c2e20f62e87  html-trap.procmail
6f16c86776c966854672d564eb66b636  html-trap.procmail.nomacroscan
88d92dcfa8480765e4dc8a5997615b37  procmail-sanitizer.tar.gz


- From the changelog:
02/11/2004 (1.140)
Make Smart Sender Notification Suppression a bit smarter - see SECURITY_TRUSTED_MTAS.
Fix DISCARD and NOTIFY tie-in - can now DISCARD without notifying.
Clean up .tmp files on mimencode failure.

NOTE: Please either update to this version or apply the
1.139 patch from the website. The stock 1.139 sanitizer
responds to NovArg/MyDoom attack messages, which forge the
sender address. This generates a great deal of useless
email.

The sanitizer home page is at
http://www.impsec.org/email-tools/procmail-security.html

The archive of the sanitizer discussion list is at
http://www.spconnect.com/mailman/listinfo/esd-l



-----BEGIN PGP SIGNATURE-----
Version: PGP 5.0
Charset: noconv

iQA/AwUBQCt8INgi5ua4cy55EQIa/wCgv139V4ZEuoFWNGGbVnLOhCTR3KsAn3wG
q+uQF9A9f3ygSVagdKCi5rHY
=fxjv
-----END PGP SIGNATURE-----

--
 John Hardin KA7OHZ    ICQ#15735746    http://www.impsec.org/~jhardin/
 jhardin at impsec.org                        pgpk -a jhardin at impsec.org
 key: 0xB8732E79 - 2D8C 34F4 6411 F507 136C  AF76 D822 E6E6 B873 2E79
-----------------------------------------------------------------------
  "Bother," said Pooh as he struggled with /etc/sendmail.cf, "it never
  does quite what I want. I wish Christopher Robin was here."
				-- Peter da Silva in a.s.r



More information about the esa-l mailing list