[alt.security] mailing to uudecode

tchrist@convex.COM (Tom Christiansen) (05/14/91)

From the keyboard of Gord_Wait@mindlink.bc.ca (Gord Wait):
:On sun sparc os 4.1.1 there is a default mail alias called uudecode. Is this a
:useful thing? I can't get it to do anything but spit out error messages when I
:mail it uuencoded files. Any clues appreciated.

It is usually more useful to a cracker than to you, as it usually allows
him to overwrite daemon-writable files anywhere on the system, or to
create setuid-daemon programs.  Depending on your sendmail, it may
even be worse than this.

I suggest you expurgate it from your system in all due haste.

--tom
--
Tom Christiansen		tchrist@convex.com	convex!tchrist
		"So much mail, so little time."