Hello all,
I belive one of our systems has been comprimised through imapd.
Does anyone know if the imapd v11.241 server for linux is succeptable
to a remote buffer overflow? I think that's what might have
happened. The cert advisory was for version 10.234, so it might
be a new bug.
I have attached some excerpts from the system logs. Each of these
messages were repeated about 15 times.
Thanks in advance,
Chris Brown
[EMAIL PROTECTED]
*********************************************************************
Chris Brown [EMAIL PROTECTED] !!! HELP FIGHT SPAM !!!
Join; www.cauce.org See; spam.abuse.net, spamsucks.com, www.cm.org
****************************************************************
-------------- Enclosure number 1 ----------------
* This message contains the file 'DANUHOH', which has been
* uuencoded. If you are using Pegasus Mail, then you can use
* the browser's eXtract function to lift the original contents
* out to a file, otherwise you will have to extract the message
* and uudecode it manually.
begin 660 DANUHOH
M9&%E;6]N+FQO9RXP.DIU;B`Q.2`P-SHS,3HQ-2!86%A86%@@:6UA<&1;,38U
M,3A=.B!C;VYN96-T(&9R;VT@8VEN97%U86YO;BYC;VT-"F1A96UO;BYL;V<N
M,#I*=6X@,3D@,#<Z-#8Z-#4@6%A86%A8(&EM87!D6S$V-3DX73H@8V]N;F5C
M="!F<F]M(&-I;F5Q=6%N;VXN8V]M#0IM86EL+FEN9F\N,#I*=6X@,3D@,#<Z
M,S$Z,C4@6%A86%A8(&EM87!D6S$V-3$W73H@8V]M;6%N9"!S=')E86T@96YD
M(&]F(&9I;&4L('=H:6QE(')E861I;F<@;&EN92!U<V5R/3\_/R!H;W-T/6-I
M;F5Q=6%N;VXN8V]M(%LR,#DN,34Q+C(S-2XR,S-=#0IM86EL+FEN9F\N,#I*
M=6X@,3D@,#<Z-#8Z-#<@6%A86%A8(&EM87!D6S$V-3@U73H@8V]M;6%N9"!S
M=')E86T@96YD(&]F(&9I;&4L('=H:6QE(')E861I;F<@;&EN92!U<V5R/3\_
M/R!H;W-T/6-I;F5Q=6%N;VXN8V]M(%LR,#DN,34Q+C(S-2XR,S-=#0IM86EL
M+FQO9RXP.DIU;B`Q.2`P-SHS,3HR-2!86%A86%@@:6UA<&1;,38U,3==.B!C
M;VUM86YD('-T<F5A;2!E;F0@;V8@9FEL92P@=VAI;&4@<F5A9&EN9R!L:6YE
M('5S97(]/S\_(&AO<W0]8VEN97%U86YO;BYC;VT@6S(P.2XQ-3$N,C,U+C(S
M,UT-"FUA:6PN;&]G+C`Z2G5N(#$Y(#`W.C0V.C0W(%A86%A86"!I;6%P9%LQ
M-C4X-5TZ(&-O;6UA;F0@<W1R96%M(&5N9"!O9B!F:6QE+"!W:&EL92!R96%D
M:6YG(&QI;F4@=7-E<CT_/S\@:&]S=#UC:6YE<75A;F]N+F-O;2!;,C`Y+C$U
,,2XR,S4N,C,S70T*
`
end
-
[To unsubscribe, send mail to [EMAIL PROTECTED] with
"unsubscribe firewalls" in the body of the message.]