[Raw Msg Headers][Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Zmailer denial-of-service attack




On Mon, 12 Feb 1996, Steve Kotsopoulos wrote:

> > The following message will cause the Zmailer 2.99.26 (probably 
> > earlier versions too) router to dump core.
> 
> It didn't bother zmailer-2.2e6, though.
> Here are the router log messages from it:
> 
> router: unknown envelope header: env-end
> squirrel: 3196 saved for inspection: unrecognized envelope information

  Has anyone ever looked at ftp://ftp.uunet.ca/incoming/zmailer.951003.tar.gz
before?

  This is a Zmailer variant that is post 2.2 and appears to have been worked 
on by Rayan at one time or another, and seems to be close to what is 
included in Border.

  Also, UUNET Canada runs Zmailer on their hosts, but this Zmailer is not 
2.99.X, or 2.2.X (supports ESMTP, and has updated copyright to 1995). 

Tom