Re: a holiday gift from Robert "wormer" Morris

Paul Vixie (
6 Nov 88 19:36:10 GMT

# the hole [in sendmail] was so obvious that i surmise that Morris
# was not the only one to discover it. perhaps other less
# reproductively minded arpanetters have been having a field
# 'day' ever since this bsd release happened.

I've known about it for a long time. I thought it was common knowledge
and that the Internet was just a darned polite place. (I think it _was_
common knowledge among the people who like to diddle the sendmail source.)

The bug in fingerd was a big surprise, though. Overwriting a stack frame
on a remote machine with executable code is One Very Neat Trick.

Paul Vixie
Work:	 decwrl!vixie	 +1 415	853 6600
Play:	 vixie!paul	 +1 415	864 7013

