Skip to content

Justin's Linklog Posts

Links for 2010-03-18

spamass-milter != SpamAssassin

Just heading this one off before it gets too much further…

A couple of weeks ago, a researcher found a bug in the spamass-milter project, an open-source milter to integrate SpamAssassin filtering into an MTA. Here’s the exploit details.

This H-Online story covered it:

Security vulnerability in SpamAssassin filter module

The SpamAssassin Milter plug-in which plugs in to Milter and calls SpamAssassin, contains a security vulnerability which can be exploited by attackers using a crafted email to inject and execute code on a mail server. The SpamAssassin Milter plug-in is frequently used to run SpamAssassin on Postfix servers.

(I think this is the source article on Heise.de.)

That was more-or-less accurate — but the problem is the “chinese whispers” effect, where a news story on another site builds on misreadings of another news article. eSecurityPlanet:

Security Flaw Found in SpamAssassin Plug-in

The SpamAssassin Milter plug-in has been found to contain a security vulnerability. […]

sigh.

To clarify: spamass-milter is not a part of SpamAssassin. it’s a third-party product which allows sendmail/postfix users to integrate spamassassin into their message flows as a milter.

Links for 2010-03-16

Links for 2010-03-08

Links for 2010-03-01

Links for 2010-02-24

  • Phishing in Irish : someone has gone to the trouble of translating the ‘Hang Seng Bank’ phish to Gaeilge. I would surmise that some phisher has a table of CCTLD-to-language mappings and is pasting their text into Google Translate before spamming their .ie address list. If only they knew how few people can read it!
    (tags: irish gaeilge funny languages translation)

Links for 2010-02-19

Links for 2010-02-12

Links for 2010-02-05

Links for 2010-02-03

Links for 2010-02-02

Links for 2010-01-28

Links for 2010-01-27

Links for 2010-01-26

Links for 2010-01-22

Links for 2010-01-21

Links for 2010-01-20

Links for 2010-01-14