<?xml version="1.0"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>CKAN: Ticket #871: Check whether localhost-only exim installtions need upgrading too</title>
    <link>http://localhost/ticket/871</link>
    <description>&lt;p&gt;
The infamous &lt;a class="ext-link" href="http://www.exim.org/lurker/message/20101207.215955.bb32d4f2.en.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;exim bug&lt;/a&gt; only needs one mail with prepared headers to travel through a exim system infect it. All local processes could do that, and some services (e.g. cron, webapps) send messages and might be convinced by malicious remote users to produce evil headers.
&lt;/p&gt;
&lt;p&gt;
We should either rule out that this could happen on our systems, or upgrade all exims regardless of whether they are localhost-only or not.
&lt;/p&gt;
&lt;p&gt;
BTW did we already run a rootkit checker like &lt;a class="ext-link" href="http://rkhunter.sourceforge.net/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;Rootkit hunter&lt;/a&gt; on eu1? If not we should maybe do it now - there was already an exploit out in the wild. &lt;a class="missing wiki"&gt;ByteMark?&lt;/a&gt; has (a) already observed infections and (b) notified us because they remotely fingerprinted our mailer to be exim&amp;lt;4.70 (our EHLO banner contains the exim version), just as anyone could.
&lt;/p&gt;
</description>
    <language>en-us</language>
    <image>
      <title>CKAN</title>
      <url>http://assets.okfn.org/p/ckan/img/ckan_logo_shortname.png</url>
      <link>http://localhost/ticket/871</link>
    </image>
    <generator>Trac 0.12.3</generator>
    <item>
      
        <dc:creator>wwaites</dc:creator>

      <pubDate>Tue, 14 Dec 2010 10:26:01 GMT</pubDate>
      <title></title>
      <link>http://localhost/ticket/871#comment:1</link>
      <guid isPermaLink="false">http://localhost/ticket/871#comment:1</guid>
      <description>
        &lt;p&gt;
Regarding rkhunter -- yes, eu1 appears to be clean
&lt;/p&gt;
&lt;p&gt;
Regarding the upgrade -- upgradede to 4.72 from backports which, looking more closely, appears to still have the privilege escalation bug but not the remote root exploit.
&lt;/p&gt;
&lt;p&gt;
Regarding exim on other hosts, there is no reason for them to be running a full mta, something like ssmtp should suffice.
&lt;/p&gt;
&lt;p&gt;
Also very worth the thought of moving to postfix. It's much easier to configure and I haven't known it to have any comparable bugs in the decade or so I've been running it. In fact I've never seen anyone actually use exim before...
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>nils.toedtmann</dc:creator>

      <pubDate>Tue, 14 Dec 2010 10:47:36 GMT</pubDate>
      <title></title>
      <link>http://localhost/ticket/871#comment:2</link>
      <guid isPermaLink="false">http://localhost/ticket/871#comment:2</guid>
      <description>
        &lt;p&gt;
Re postfix: I second ww. I like to run some super simple local MTA (e.g. "nullmailer") on all but one server, using a central postfix (or a send-only GMail account) as smarthost. Am happy with postfix for &amp;gt;10years, it's straightforward and rock solid.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>rgrp</dc:creator>

      <pubDate>Sat, 29 Jan 2011 22:35:58 GMT</pubDate>
      <title>status changed; resolution set</title>
      <link>http://localhost/ticket/871#comment:3</link>
      <guid isPermaLink="false">http://localhost/ticket/871#comment:3</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;status&lt;/strong&gt;
                changed from &lt;em&gt;new&lt;/em&gt; to &lt;em&gt;closed&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;resolution&lt;/strong&gt;
                set to &lt;em&gt;invalid&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
This is not a ckan issue. should have been on &lt;a class="ext-link" href="http://knowledgeforge.net/okfn/tasks"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://knowledgeforge.net/okfn/tasks&lt;/a&gt;
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item>
 </channel>
</rss>