|
|
|
![]() |
Vulnerability Note VU#814617IBM AIX sendmail configured as open mail relay by defaultOverviewSendmail shipped with IBM AIX is configured by default as an open mail relay. Unauthenticated, remote users can route mail through such a system.I. DescriptionSendmail is a widely used mail transfer agent (MTA) that is included with IBM AIX. According to IBM:The default configuration files for sendmail enable three sendmail options which allow arbitrary users to route email via sendmail. The options are "promiscuous_relay", "accept_unresolvable_domains" and "accept_unqualified_senders". II. ImpactAny remote user can route mail through sendmail on a vulnerable IBM AIX system. This configuration is called an "open relay" and such systems are frequently abused to deliver unsolicited commercial email (UCE) or SPAM.III. SolutionModify sendmail ConfigurationConfigure sendmail not to accept messages addressed from and to foreign domains on behalf of unauthenticated users. IBM has released an advisory and updated configuration files for sendmail on AIX:
Using a firewall or similar technology, block access to vulnerable AIX sendmail systems (SMTP 25/tcp) from untrusted networks such as the Internet. Systems Affected
References
This vulnerability was reported by Tom Perrine of the San Diego Supercomputer Center. This document was written by Art A Manion.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||