No....the LDAP that came with Imail Orginally and the LDAP it uses if you
don't convert to OpenLDAP.

Travis

> -----Original Message-----
> From: [EMAIL PROTECTED]
> [mailto:[EMAIL PROTECTED] Behalf Of Rick Klinge
> Sent: Friday, May 07, 2004 7:33 AM
> To: [EMAIL PROTECTED]
> Subject: RE: [IMail Forum] DAMN LDAP EXPLOIT! Take it seriously
>
>
> Jay,
>
> Isn't this the "Free" Open Source LDAP stuff?  It looks like all they did
> was hack up the opensouce product and interweaved it into there own.
> Correct me if I'm wrong, please, but if this being the case the I would
> foresee a lot of patches and updates coming down the pipe just to
> keep LDAP
> secure.
>
> ~Rick
>
> >
> > Of course you didn't know.  IPSwitch calls the vulnerability
> > a denial of service attack, when it's in fact a remote code
> > execution attack.  Any remote code execution attack,
> > especially against a service running in the LocalSystem
> > Context by default is going to be severe.
> >
> > In this day and age, it's down right negligent to be
> > misinforming your customers about security vulnerabilities.
> > Yet, IPSwitch has no problem calling this issue a "possible
> > LDAP Denial of Service vulnerability", which is just a flat
> > out lie.  It's a remote code execution vulnerability with
> > exploits in the wild.
> >
> > Ughs ...
> >
> > Jay Sudowski
> >
> > Director of Technical Operations
> > -----------------------------------------
> > HANDY NETWORKS, LLC
> > Tel.: 1-877-70-HANDY Ext. 882
> > Fax: 1-888-800-2FAX
> > http://www.HandyNetworks.com
> > ICQ 15601511  |  AIM JaySuds
> > ----------------------------------------
> > Specializing in Windows 2000 Hosting Solutions
> > Bulk Reseller Hosting / Managed Dedicated Services
> > Managed Dedicated Server Specials from $299
> >
> >
> >
> >
> > -----Original Message-----
> > From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]
> > Sent: Friday, May 07, 2004 12:42 AM
> > To: [EMAIL PROTECTED]
> > Subject: [IMail Forum] DAMN LDAP EXPLOIT! Take it seriously
> >
> > I had to move a box that is hosted for me offsite.  I was on
> > 7.15 so installed it on the new box, then moved over my old
> > IMAIL to the new box. Upgraded to 8.05 installed, Declude,
> > anti-virus and so on and then applied HF3....
> > I have been so badly hacked through the LDAP exploit that I
> > have to move to a new box.  He also used my box to scan and
> > compromise other IMAIL servers, I have IPS of possible other
> > hacked IMAIL machines (I'm tempted to post them, but I will
> > try to spend some time when I have it trying to figure out if
> > I can contact these people - unless people feel I should post
> > them) . I have spent over three days pouring through my box,
> > pulling out installed programs, batch files, registry entries
> > and still this guy is running an FTP service on port 4022
> > that I can't find the program, service or files that are
> > being uploaded and downloaded.  The only thing that alerted
> > me to this was the IPNT.NET tech calling me telling me about
> > traffic spikes on my box at 2am.
> >
> > Virus scans found nothing, spyware scans found nothing.  If
> > doing a new install of anything below 8.1 I STRONGLY suggest
> > that you stop the LDAP service immediately and PATCH!!!  I
> > had no idea that this exploit was so bad.
> >
> >
>
> ___________________________________________________________________
> Virus Scanned and Filtered by http://www.FamHost.com E-Mail System.
>
>
> To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
> List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
> Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
>



To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to