home.social

#qmail — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #qmail, aggregated by home.social.

  1. #Claude Code fand eine Remote Code Execution in einer populären Distribution des Mailservers #qmail.

    Das Problem lag an #popen und man benötigt einen wunderschönen MX-Record der Form:

    x'`id>/tmp/pwned`'y.example.com

    Das "reine" qmail von @djb ist nicht betroffen.

    blog.calif.io/p/we-asked-claud

    github.com/califio/publication

    #RCE #security #mail #MTA #Mailserver

  2. @dangoodin @djb @0x0FFF

    Dan G.: to butt in, from experience with #djb from mailing lists for #qmail, #djbdns, etc...

    When djb states facts, he is invariably correct. When he presents a logical argument, he is rigorous, but it is frequently non-trivial to follow. Very dense logic, and perhaps omission of the more "obvious" steps, mean you can't grasp it on first read.

    When taking apart someone else's argument, it's even denser and crammed with references. But worth it. Spend the time.