Thanks for that confident and reassuring reply Daniel! -V ----- Original Message ----- From: Daniel Donnelly <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Friday, June 18, 1999 10:50 AM Subject: Re: [IMail Forum] Does IPSwitch have an Answer for this? - Security Alert > Old news! If one looks in his Release Notes and has V5.03 or later, you would > see that these have been addressed. You can also find Release notes in our > KnowledgeBase. > > Daniel Donnelly > Ipswitch Technical Support > ________________________________________________________ > See our Knowledge Base at http://support.ipswitch.com/kb > URL for List Servers: http://www.ipswitch.com/Support/mailing-lists.html > > > In reply to 17 Jun message from [EMAIL PROTECTED]: > > >Multiple IMail Vulnerabilites > > >Systems Affected > >IMail 5.0 > > >Release Date > >March 1, 1999 > > >Advisory Code > >AD03011999 > > >Description: > > >The following holes can be used as a Denial of Service against the > >various services mentioned and in some cases used to remotely execute > >code. > > >Imapd (143) > > >The imapd login process does not do proper bounds checking on usernames > >and passwords. > > >* OK IMAP4 Server (IMail 4.06) > >X LOGIN glob1 glob2 > > >Where glob1 is 1200 characters and glob2 is 1300 characters. The imapd > >service will crash with the usuall overflow error. > > >LDAP (389) > > >Telnet to server.com 389 > >Send: Y glob1 > >hit enter twice > >Server Returns: 0 > >Send: Y glob2 > >hit enter > > >Where glob1 and glob2 are 2375 characters and Y is Y. The ldap service > >goes to 90 percent or so and idles there. Therefore using up most > system > >resources. > > >IMonitor (8181) > > >Telnet to server.com 8181 > >Send: glob1 > >hit enter twice > > >Where glob1 is 2045 characters. The IMonitor service crashes with the > >normal overflow message. > > >IMail Web Service (8383) > > >Telnet to server.com 8383 > >Send: GET /glob1/ > > >Where glob1 is 3000 characters. The usual overflow message will be > >displayed. This one looks to be easily exploitable. >:-] > > >Whois32 Daemon (43) > > >Telnet to server.com 43 > >Send glob1 > > >Where glob1 is 1000 characters. The usual overflow message will be > >displayed. Ya... starting to sound old. > > >Vendor Status > > >Vendor has been notified, Waiting for response... > > >Copyright (c) 1999 eEye Digital Security Team > >Permission is hereby granted for the redistribution of this alert > >electronically. It is not to be edited in any way without express > >consent of eEye. If you wish to reprint the whole or any part of this > >alert in any other medium excluding electronic medium, please e-mail > >[EMAIL PROTECTED] for permission. > > >Disclaimer: > > >The information within this paper may change without notice. Use of > this > >information constitutes acceptance for use in an AS IS condition. There > >are NO warranties with regard to this information. In no event shall > the > >author be liable for any damages whatsoever arising out of or in > >connection with the use or spread of this information. Any use of this > >information is at the user's own risk. > > >Please send suggestions, updates, and comments to: > > >eEye Digital Security Team > > >[EMAIL PROTECTED] > >http://www.eEye.com > > >-Mark McDonald > >[EMAIL PROTECTED] > > >Voice: 800.610.9856, Ext. 231 - Fax: 888.333.2710 > > > >
