Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. I laughed at the description of `sendmail` as “... less a mail transfer agent and more a recurring CVE subscription.”

I laughed at the description of `sendmail` as “... less a mail transfer agent and more a recurring CVE subscription.”

Scheduled Pinned Locked Moved Uncategorized
qmailsecurityrisksmail
4 Posts 2 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • angusm@mastodon.socialA This user is from outside of this forum
    angusm@mastodon.socialA This user is from outside of this forum
    angusm@mastodon.social
    wrote last edited by
    #1

    I laughed at the description of `sendmail` as “... less a mail transfer agent and more a recurring CVE subscription.”

    Link Preview Image
    We Asked Claude to Audit Sagredo's qmail. It found a RCE.

    One prompt, 101 minutes, and a working exploit against a widely deployed qmail fork.

    favicon

    (blog.calif.io)

    #qmail #security #risks #mail

    david_chisnall@infosec.exchangeD 1 Reply Last reply
    0
    • angusm@mastodon.socialA angusm@mastodon.social

      I laughed at the description of `sendmail` as “... less a mail transfer agent and more a recurring CVE subscription.”

      Link Preview Image
      We Asked Claude to Audit Sagredo's qmail. It found a RCE.

      One prompt, 101 minutes, and a working exploit against a widely deployed qmail fork.

      favicon

      (blog.calif.io)

      #qmail #security #risks #mail

      david_chisnall@infosec.exchangeD This user is from outside of this forum
      david_chisnall@infosec.exchangeD This user is from outside of this forum
      david_chisnall@infosec.exchange
      wrote last edited by
      #2

      @angusm

      Is that code really using popen invoking touch to do the equivalent of open?

      angusm@mastodon.socialA 1 Reply Last reply
      0
      • david_chisnall@infosec.exchangeD david_chisnall@infosec.exchange

        @angusm

        Is that code really using popen invoking touch to do the equivalent of open?

        angusm@mastodon.socialA This user is from outside of this forum
        angusm@mastodon.socialA This user is from outside of this forum
        angusm@mastodon.social
        wrote last edited by
        #3

        @david_chisnall Feels like the kind of vulnerability that you shouldn’t need 101 minutes of “AI” time to detect.

        david_chisnall@infosec.exchangeD 1 Reply Last reply
        0
        • angusm@mastodon.socialA angusm@mastodon.social

          @david_chisnall Feels like the kind of vulnerability that you shouldn’t need 101 minutes of “AI” time to detect.

          david_chisnall@infosec.exchangeD This user is from outside of this forum
          david_chisnall@infosec.exchangeD This user is from outside of this forum
          david_chisnall@infosec.exchange
          wrote last edited by
          #4

          @angusm

          I don't know, you'd probably have to pay a human a lot to be willing to look at code like that...

          1 Reply Last reply
          1
          0
          • R relay@relay.infosec.exchange shared this topic
          Reply
          • Reply as topic
          Log in to reply
          • Oldest to Newest
          • Newest to Oldest
          • Most Votes


          • Login

          • Login or register to search.
          • First post
            Last post
          0
          • Categories
          • Recent
          • Tags
          • Popular
          • World
          • Users
          • Groups