Re: Lotus Domino DoS

From: 3APA3A (3APA3A@SECURITY.NNOV.RU)
Date: 08/21/01


Date: Tue, 21 Aug 2001 12:47:35 +0400
From: 3APA3A <3APA3A@SECURITY.NNOV.RU>
Message-ID: <77256949073.20010821124735@sandy.ru>
To: Ian Gulliver <ian@orbz.org>
Subject: Re: Lotus Domino DoS

Dear Ian Gulliver,

--21.08.2001 1:19, you wrote Lotus Domino DoS to bugtraq@securityfocus.com;

I> MAIL FROM:<bounce@[127.0.0.1]> RCPT
I> TO:<address@domain.com>

I> where domain.com is not local to the server in question,
I> the server attempts to bounce the message, and the bounce
I> goes into a loop, constantly being sent back to the same
I> server.

It was reported in vuln-dev list on May, 20 2000 by SMILER
<smiler@VXD.ORG> in same time with SMTP buffer overflow in
Lotus. I wonder why it's not patched yet.

http://www.security.nnov.ru/search/document.asp?docid=226

-- 
/3APA3A



Relevant Pages

  • Re: reject messages to a domain
    ... Exchange SMTP, it bounced immediately with the message: ... The destination server for this recipient could not be found in Domain ... Yes, if the domain is not-existent, it should bounce back immediately. ... I've made an SMTP connector with address space set to ...
    (microsoft.public.exchange.admin)
  • Re: reject messages to a domain
    ... The destination server for this recipient could not be found in Domain ... Yes, if the domain is not-existent, it should bounce back immediately. ... Is there something wrong with connector I configured? ... The SMTP connector would act on mail sent *from* your server, ...
    (microsoft.public.exchange.admin)
  • Re: Mails "Bounce" feature
    ... Accept the message during its dialog with Z, but bounce the message ... So if Z is a genuine mail server ... email is accepted by the receiving server, ... this should be done by the receiving mail server ...
    (comp.sys.mac.apps)
  • Re: reject messages to a domain
    ... Exchange SMTP, it bounced immediately with the message: ... The destination server for this recipient could not be found in Domain Name ... Yes, if the domain is not-existent, it should bounce back immediately. ... Is there something wrong with connector I configured? ...
    (microsoft.public.exchange.admin)
  • Re: ruby-lang emails getting blocked
    ... an email with one of the spam trap address as the from was bounced by the ... so no human checks to see if the message was a bounce. ... spamcop would probably still list the server as a spam ... I have not been an active user of spamcop for some time. ...
    (comp.lang.ruby)

Loading