OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 

From: Hans Zaunere (zaunereyahoo.com)
Date: Mon Mar 03 2003 - 20:29:01 CST


--- Chris McCluskey <chrisdigitaldeck.com> wrote:
>
> Ok...
>
> Here's what I show:
>
> namehere# telnet namehere 25
> Trying 192.x.y.z...
> Connected to namehere.digitaldeck.com.
> Escape character is '^]'.
> 220 namehere.digitaldeck.com ESMTP Sendmail 8.12.6/8.12.6; Mon, 3 Mar
> 2003 16:22:53 -0800 (PST)
>
> namehere# strings sendmail-4.7-i386-nocrypto.bin |grep 8.12
> (#)$Id: safefile.c,v 8.124 2002/05/24 20:50:15 gshapiro Exp $
> 8.12.6
>
> I have been tracking RELENG_4_7 and it looks like 4.12.6 to me. So
> again, I want to make sure that this version of Sendmail has been
> patched. What's the best verification procedure to insure that the
> patched version is online?

I'm in the exact same situation. I replaced the sendmail binary but it shows
the same sig as before. While I have great confidence in the FreeBSD team,
is there some way I can validate everything is kosher?

Hans

To Unsubscribe: send mail to majordomoFreeBSD.org
with "unsubscribe freebsd-security" in the body of the message