Morris Worm sendmail Debug Mode Shell Escape
Posted by deepcore on November 6, 2018 – 7:30 pm
This Metasploit module exploits sendmail’s well-known historical debug mode to escape to a shell and execute commands in the SMTP RCPT TO command. This vulnerability was exploited by the Morris worm in 1988-11-02. Cliff Stoll reports on the worm in the epilogue of The Cuckoo’s Egg. Currently only cmd/unix/reverse and cmd/unix/generic are supported.
Post a reply
You must be logged in to post a comment.