[NT] Account Management Vulnerabilities in Ipswitch IMail Server
From: support@securiteam.comDate: 10/16/01
- Previous message: support@securiteam.com: "[UNIX] Bug in Linux 2.4 and IPTables MAC Match Module"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: support@securiteam.com To: list@securiteam.com Subject: [NT] Account Management Vulnerabilities in Ipswitch IMail Server Message-Id: <20011016123118.C2EF7138C1@mail.der-keiler.de> Date: Tue, 16 Oct 2001 14:31:18 +0200 (CEST)
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
When was the last time you checked your server's security?
How about a monthly report?
http://www.AutomatedScanning.com - Know that you're safe.
- - - - - - - - -
Account Management Vulnerabilities in Ipswitch IMail Server
------------------------------------------------------------------------
SUMMARY
IMail Server is a spam-resistant mail server for Windows NT/2000. The
product suffers from two security vulnerabilities; one allows username
harvesting, and the other allows modification of account information
without knowing the password for that account.
DETAILS
Vulnerable systems:
Ipswitch IMail Server version 7.04
POP3 Account disclosure:
If you enter a valid username, the reply is:
+OK welcome
On the other hand, if you enter a username that does not exist on the
server the reply is:
+OK send your password
This gives you a way to probe for existing accounts on the server.
Web Messaging Server Account Modification :
Log in on one account in the Web Messaging Server and Select Change User
Information. Save the HTML page on disk and change the value of the hidden
INPUT tag called "olduser" to the name of another account. You also have
to change the ACTION value of the FORM tag so it points to the server, and
it must contain the random string that you find in the URL to the ordinary
page. Next, load this changed page into the browser, fill in some new user
information and click on the Save button. This way you can change the user
information for any other user.
Vendor response:
Ipswitch have created a patch that among other things fixes these two
vulnerabilities. You can find it at:
<http://www.ipswitch.com/support/IMail/patch-upgrades.html>
http://www.ipswitch.com/support/IMail/patch-upgrades.html
ADDITIONAL INFORMATION
The information has been provided by <mailto:arne.vidstrom@ntsecurity.nu>
Arne Vidstrom.
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Previous message: support@securiteam.com: "[UNIX] Bug in Linux 2.4 and IPTables MAC Match Module"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
- Re: FTP Tagging anyone?
... > secured against various different kinds of vulnerabilities, ... formatting
the system is probably not necessary. ... baseline server looks like, so they can't tell
what is and isn't suspicious ... this depends on your security needs. ... (microsoft.public.inetserver.iis.security) - Multiple Vulnerabilities Sybase Anywhere 9
... NGSSoftware Insight Security Research Advisory ... Multiple Vulnerabilities
in Adaptive Server Anywhere Network Server ... attack allowing an authenticated user to
escalate privileges to 'dba' within ... (NT-Bugtraq) - Re: having problems creating packages - access denied..
... I've given a global group (which contains all of the site server computer ...
full share permission and also full local security permission. ... SMS uses the site
server computer account to connect to ... (microsoft.public.sms.admin) - Mysterious "Support" account created on Win2k server
... One of my web servers appears to have had an intrusion. ... Advanced Server,
SP3, up to date on all security patches. ... I discovered that the Local Security ...
single local account called "Support" that I did not recognize. ... (Incidents) - Re: Anonymous Account not working
... I don't see any security log entries. ... I think the problem may be with the
local account. ... built the server there was another server that was named WEB02,
... renamed this server (so that the iusr and iwam accounts would be ... (microsoft.public.inetserver.iis.security)