Got it.  Guess I'll still leave is disabled and wait till 8.11 is granite.

~Rick

> 
> No....the LDAP that came with Imail Orginally and the LDAP it 
> uses if you don't convert to OpenLDAP.
> 
> Travis
> 
> > -----Original Message-----
> > From: [EMAIL PROTECTED]
> > [mailto:[EMAIL PROTECTED] Behalf Of Rick Klinge
> > Sent: Friday, May 07, 2004 7:33 AM
> > To: [EMAIL PROTECTED]
> > Subject: RE: [IMail Forum] DAMN LDAP EXPLOIT! Take it seriously
> >
> >
> > Jay,
> >
> > Isn't this the "Free" Open Source LDAP stuff?  It looks 
> like all they 
> > did was hack up the opensouce product and interweaved it into there 
> > own. Correct me if I'm wrong, please, but if this being the 
> case the I 
> > would foresee a lot of patches and updates coming down the 
> pipe just 
> > to keep LDAP secure.
> >
> > ~Rick
> >
> > >
> > > Of course you didn't know.  IPSwitch calls the vulnerability a 
> > > denial of service attack, when it's in fact a remote code 
> execution 
> > > attack.  Any remote code execution attack, especially against a 
> > > service running in the LocalSystem Context by default is 
> going to be 
> > > severe.
> > >
> > > In this day and age, it's down right negligent to be misinforming 
> > > your customers about security vulnerabilities. Yet, 
> IPSwitch has no 
> > > problem calling this issue a "possible LDAP Denial of Service 
> > > vulnerability", which is just a flat out lie.  It's a remote code 
> > > execution vulnerability with exploits in the wild.
> > >
> > > Ughs ...
> > >
> > > Jay Sudowski
> > >
> > > Director of Technical Operations
> > > -----------------------------------------
> > > HANDY NETWORKS, LLC
> > > Tel.: 1-877-70-HANDY Ext. 882
> > > Fax: 1-888-800-2FAX
> > > http://www.HandyNetworks.com
> > > ICQ 15601511  |  AIM JaySuds
> > > ----------------------------------------
> > > Specializing in Windows 2000 Hosting Solutions
> > > Bulk Reseller Hosting / Managed Dedicated Services
> > > Managed Dedicated Server Specials from $299
> > >
> > >
> > >
> > >
> > > -----Original Message-----
> > > From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]
> > > Sent: Friday, May 07, 2004 12:42 AM
> > > To: [EMAIL PROTECTED]
> > > Subject: [IMail Forum] DAMN LDAP EXPLOIT! Take it seriously
> > >
> > > I had to move a box that is hosted for me offsite.  I was 
> on 7.15 so 
> > > installed it on the new box, then moved over my old IMAIL 
> to the new 
> > > box. Upgraded to 8.05 installed, Declude, anti-virus and 
> so on and 
> > > then applied HF3.... I have been so badly hacked through the LDAP 
> > > exploit that I have to move to a new box.  He also used my box to 
> > > scan and compromise other IMAIL servers, I have IPS of possible 
> > > other hacked IMAIL machines (I'm tempted to post them, but I will
> > > try to spend some time when I have it trying to figure out if
> > > I can contact these people - unless people feel I should post
> > > them) . I have spent over three days pouring through my box,
> > > pulling out installed programs, batch files, registry entries
> > > and still this guy is running an FTP service on port 4022
> > > that I can't find the program, service or files that are
> > > being uploaded and downloaded.  The only thing that alerted
> > > me to this was the IPNT.NET tech calling me telling me about
> > > traffic spikes on my box at 2am.
> > >
> > > Virus scans found nothing, spyware scans found nothing.  
> If doing a 
> > > new install of anything below 8.1 I STRONGLY suggest that 
> you stop 
> > > the LDAP service immediately and PATCH!!!  I had no idea 
> that this 
> > > exploit was so bad.
> > >
> > >

___________________________________________________________________
Virus Scanned and Filtered by http://www.FamHost.com E-Mail System.


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to