junkbuster 2.0-1 proxy relaying spam

From: Andrew Daviel (andrew@andrew.triumf.ca)
Date: 12/23/02

  • Next message: Marc Slemko: "Re: 'printenv' XSS vulnerability"
    Date: Mon, 23 Dec 2002 02:11:41 -0800 (PST)
    From: Andrew Daviel <andrew@andrew.triumf.ca>
    To: BUGTRAQ@SECURITYFOCUS.COM
    
    

    I just found a "junkbuster" proxy on a RedHat 6.2 machine
    being used to relay spam - a bit ironic, considering the
    intention of the program.

    This is junkbuster-2.0-1 installed as part of a
    "complete install" on RedHat 6.2.
    It seems that the default install sets no ACL, no logging,
    and starts the program on boot.

    This is not the buffer overflow reported in 1998. It is
    a simple use of the HTTP CONNECT method similar to the Korean
    school Apache proxies

    The default for junkbuster 2.0-2 is to listen on localhost only,
    so modern installs should be safe.

    -- 
    Andrew Daviel, TRIUMF, Canada
    Tel. +1 (604) 222-7376
    security@triumf.ca
    


    Relevant Pages

    • Re: OpenQM vs. Everything Else
      ... people who "support" Linux really only install stock distros. ... Debian is simply not drama queen. ... Linux or that of people like Martin, Doug, or other "engineer" types ... U2, RedHat and SuSE: ...
      (comp.databases.pick)
    • Re: samba and lan with winxp and linux computers
      ... I added a fourth computer running Redhat Linux 9 personal edition. ... | read the redhat documentation and the samba documentation and these ... | install any samba components by default. ... | now for the windows network but it still can't see the windows ...
      (alt.os.linux.redhat)
    • Re: samba
      ... Verify your system has all the BOS sub packages from the AIX install ... winbind use default domain = Yes ... valid users = @dev, @REDHAT ...
      (comp.unix.aix)
    • Re: Viruses and hackers make Windows more secure - Gates
      ... Windows, I'm running Linux. ... But I have to remind you, that Redhat is not Linux. ... You can chose to install workstation ...
      (alt.computer.security)
    • Re: Dual head display with RedHat 9.0?
      ... How does one configure RedHat 9.0 for a dual-hdr display? ... The install goes well - no apparent problems. ... >With the first install I basically punted on video card and monitor ... RedHat Linux looks pretty nice, including the desktop. ...
      (linux.redhat.install)