No it's not the same. The exploit is with the old LDAP service in pre-8.1 implementations. The current implementation was not interweaved into the old LDAP code. It completely replaced it. I would suggest that any patch that fixes any exploit, no matter how it's worded in the release notes, be taken seriously and people should patch their systems.
-----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Behalf Of Rick Klinge Sent: Friday, May 07, 2004 10:33 AM To: [EMAIL PROTECTED] Subject: RE: [IMail Forum] DAMN LDAP EXPLOIT! Take it seriously Jay, Isn't this the "Free" Open Source LDAP stuff? It looks like all they did was hack up the opensouce product and interweaved it into there own. Correct me if I'm wrong, please, but if this being the case the I would foresee a lot of patches and updates coming down the pipe just to keep LDAP secure. ~Rick > > Of course you didn't know. IPSwitch calls the vulnerability > a denial of service attack, when it's in fact a remote code > execution attack. Any remote code execution attack, > especially against a service running in the LocalSystem > Context by default is going to be severe. > > In this day and age, it's down right negligent to be > misinforming your customers about security vulnerabilities. > Yet, IPSwitch has no problem calling this issue a "possible > LDAP Denial of Service vulnerability", which is just a flat > out lie. It's a remote code execution vulnerability with > exploits in the wild. > > Ughs ... > > Jay Sudowski > > Director of Technical Operations > ----------------------------------------- > HANDY NETWORKS, LLC > Tel.: 1-877-70-HANDY Ext. 882 > Fax: 1-888-800-2FAX > http://www.HandyNetworks.com > ICQ 15601511 | AIM JaySuds > ---------------------------------------- > Specializing in Windows 2000 Hosting Solutions > Bulk Reseller Hosting / Managed Dedicated Services > Managed Dedicated Server Specials from $299 > > > > > -----Original Message----- > From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] > Sent: Friday, May 07, 2004 12:42 AM > To: [EMAIL PROTECTED] > Subject: [IMail Forum] DAMN LDAP EXPLOIT! Take it seriously > > I had to move a box that is hosted for me offsite. I was on > 7.15 so installed it on the new box, then moved over my old > IMAIL to the new box. Upgraded to 8.05 installed, Declude, > anti-virus and so on and then applied HF3.... > I have been so badly hacked through the LDAP exploit that I > have to move to a new box. He also used my box to scan and > compromise other IMAIL servers, I have IPS of possible other > hacked IMAIL machines (I'm tempted to post them, but I will > try to spend some time when I have it trying to figure out if > I can contact these people - unless people feel I should post > them) . I have spent over three days pouring through my box, > pulling out installed programs, batch files, registry entries > and still this guy is running an FTP service on port 4022 > that I can't find the program, service or files that are > being uploaded and downloaded. The only thing that alerted > me to this was the IPNT.NET tech calling me telling me about > traffic spikes on my box at 2am. > > Virus scans found nothing, spyware scans found nothing. If > doing a new install of anything below 8.1 I STRONGLY suggest > that you stop the LDAP service immediately and PATCH!!! I > had no idea that this exploit was so bad. > > ___________________________________________________________________ Virus Scanned and Filtered by http://www.FamHost.com E-Mail System. To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/ To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
