Got it. Guess I'll still leave is disabled and wait till 8.11 is granite. ~Rick
> > No....the LDAP that came with Imail Orginally and the LDAP it > uses if you don't convert to OpenLDAP. > > Travis > > > -----Original Message----- > > From: [EMAIL PROTECTED] > > [mailto:[EMAIL PROTECTED] Behalf Of Rick Klinge > > Sent: Friday, May 07, 2004 7:33 AM > > To: [EMAIL PROTECTED] > > Subject: RE: [IMail Forum] DAMN LDAP EXPLOIT! Take it seriously > > > > > > Jay, > > > > Isn't this the "Free" Open Source LDAP stuff? It looks > like all they > > did was hack up the opensouce product and interweaved it into there > > own. Correct me if I'm wrong, please, but if this being the > case the I > > would foresee a lot of patches and updates coming down the > pipe just > > to keep LDAP secure. > > > > ~Rick > > > > > > > > Of course you didn't know. IPSwitch calls the vulnerability a > > > denial of service attack, when it's in fact a remote code > execution > > > attack. Any remote code execution attack, especially against a > > > service running in the LocalSystem Context by default is > going to be > > > severe. > > > > > > In this day and age, it's down right negligent to be misinforming > > > your customers about security vulnerabilities. Yet, > IPSwitch has no > > > problem calling this issue a "possible LDAP Denial of Service > > > vulnerability", which is just a flat out lie. It's a remote code > > > execution vulnerability with exploits in the wild. > > > > > > Ughs ... > > > > > > Jay Sudowski > > > > > > Director of Technical Operations > > > ----------------------------------------- > > > HANDY NETWORKS, LLC > > > Tel.: 1-877-70-HANDY Ext. 882 > > > Fax: 1-888-800-2FAX > > > http://www.HandyNetworks.com > > > ICQ 15601511 | AIM JaySuds > > > ---------------------------------------- > > > Specializing in Windows 2000 Hosting Solutions > > > Bulk Reseller Hosting / Managed Dedicated Services > > > Managed Dedicated Server Specials from $299 > > > > > > > > > > > > > > > -----Original Message----- > > > From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] > > > Sent: Friday, May 07, 2004 12:42 AM > > > To: [EMAIL PROTECTED] > > > Subject: [IMail Forum] DAMN LDAP EXPLOIT! Take it seriously > > > > > > I had to move a box that is hosted for me offsite. I was > on 7.15 so > > > installed it on the new box, then moved over my old IMAIL > to the new > > > box. Upgraded to 8.05 installed, Declude, anti-virus and > so on and > > > then applied HF3.... I have been so badly hacked through the LDAP > > > exploit that I have to move to a new box. He also used my box to > > > scan and compromise other IMAIL servers, I have IPS of possible > > > other hacked IMAIL machines (I'm tempted to post them, but I will > > > try to spend some time when I have it trying to figure out if > > > I can contact these people - unless people feel I should post > > > them) . I have spent over three days pouring through my box, > > > pulling out installed programs, batch files, registry entries > > > and still this guy is running an FTP service on port 4022 > > > that I can't find the program, service or files that are > > > being uploaded and downloaded. The only thing that alerted > > > me to this was the IPNT.NET tech calling me telling me about > > > traffic spikes on my box at 2am. > > > > > > Virus scans found nothing, spyware scans found nothing. > If doing a > > > new install of anything below 8.1 I STRONGLY suggest that > you stop > > > the LDAP service immediately and PATCH!!! I had no idea > that this > > > exploit was so bad. > > > > > > ___________________________________________________________________ Virus Scanned and Filtered by http://www.FamHost.com E-Mail System. To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
