[Full-Disclosure] IMAP4rev1 2000.283 allows access to system files

From: Guy Cohen (fdat_private)
Date: Sat Aug 10 2002 - 10:31:31 PDT

  • Next message: Guy Cohen: "[Full-Disclosure] more about IMAP"

    Hi,
    
    This just might be misconfiguration on the one imap server I have access
    too, but It might not.
    
    when trying to check what's up with my mail using telnet, I've
    issued a command: LIST "*" "*" and to my suprise got a listing of the files
    in my directory. I could run LIST "../*" "*" and get the listing of directories
    above mine. and so forth. Well then i tought to my self how far can this go,
    so i tried SELECT "/etc/hosts"; FETCH 1 (flags rfc822.text) and guess what
    I saw... then I went on to CREATE "/tmp/MyTest". Writing into other
    files is a little tricky but can be done with append after using select to
    find out if the file is writable.
    
    
    Cheers,
      Guy
    
    -- 
    Unix Administration,       |      http://www.unixadmin.co.il
    locally and remotely.      |      supportat_private
    Planning, installation,    |      Phone: 972-3-6201373
    support & upgrades.        |      Location: Unrestricted
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    



    This archive was generated by hypermail 2b30 : Sat Aug 10 2002 - 11:05:11 PDT