Of course you didn't know.  IPSwitch calls the vulnerability a denial of
service attack, when it's in fact a remote code execution attack.  Any
remote code execution attack, especially against a service running in
the LocalSystem Context by default is going to be severe.

In this day and age, it's down right negligent to be misinforming your
customers about security vulnerabilities.  Yet, IPSwitch has no problem
calling this issue a "possible LDAP Denial of Service vulnerability",
which is just a flat out lie.  It's a remote code execution
vulnerability with exploits in the wild.

Ughs ... 

Jay Sudowski

Director of Technical Operations
-----------------------------------------
HANDY NETWORKS, LLC
Tel.: 1-877-70-HANDY Ext. 882
Fax: 1-888-800-2FAX
http://www.HandyNetworks.com 
ICQ 15601511  |  AIM JaySuds
----------------------------------------
Specializing in Windows 2000 Hosting Solutions
Bulk Reseller Hosting / Managed Dedicated Services
Managed Dedicated Server Specials from $299

 


-----Original Message-----
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] 
Sent: Friday, May 07, 2004 12:42 AM
To: [EMAIL PROTECTED]
Subject: [IMail Forum] DAMN LDAP EXPLOIT! Take it seriously

I had to move a box that is hosted for me offsite.  I was on 7.15 so
installed it on the new box, then moved over my old IMAIL to the new
box.
Upgraded to 8.05 installed, Declude, anti-virus and so on and then
applied
HF3.... 
I have been so badly hacked through the LDAP exploit that I have to move
to
a new box.  He also used my box to scan and compromise other IMAIL
servers,
I have IPS of possible other hacked IMAIL machines (I'm tempted to post
them, but I will try to spend some time when I have it trying to figure
out
if I can contact these people - unless people feel I should post them) .
I
have spent over three days pouring through my box, pulling out installed
programs, batch files, registry entries and still this guy is running an
FTP
service on port 4022 that I can't find the program, service or files
that
are being uploaded and downloaded.  The only thing that alerted me to
this
was the IPNT.NET tech calling me telling me about traffic spikes on my
box
at 2am.  

Virus scans found nothing, spyware scans found nothing.  If doing a new
install of anything below 8.1 I STRONGLY suggest that you stop the LDAP
service immediately and PATCH!!!  I had no idea that this exploit was so
bad.


---
[This E-mail scanned for viruses by Declude Virus]


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/



To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to