TCLUG Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [TCLUG:2417] Security holes in IMAP



It's all real new to me but I did a search on IMAP at rootshell.com that resulted in eight listed exploits. The one I took the time to read was dated 6-24-97 " Get remote root access on Redhat systems by overwriting a
                                    buffer in impad."

The other articles looked very interesting as well.

ron parker

Eric Hillman wrote:

I've heard that there were security holes in IMAP -- this news story
recently ran on ZDNet mentioning a worm being used to exploit them.

http://www.zdnet.com/zdnn/stories/news/0,4586,2169798,00.html

  The reason I'm interested is that recently the ipfwadm setup I have on my
home Linux server (modified from Tom Cross' "slatch" scripts) registered
unauthorized access attempts on the IMAP port -- two within a week, in fact.

  Does anybody know if this is a concern for more recent versions of IMAP?
The article says it mostly affects users of RedHat 5.0, which strikes me as
FUDdishly vague.  Also, it doesn't mention exactly what it is this worm
*does*, or how to tell if your system might have been infected.

---------------------------------------------------------------------
To unsubscribe, e-mail: tclug-list-unsubscribe@listserv.real-time.com
For additional commands, e-mail: tclug-list-help@listserv.real-time.com
Try our website: http://tclug.real-time.com

-- 
-------------------------------------------------------------------------------
Ron Parker - Web/Tech Admin                             Parker Publishing
------------------------------------------------------------------------------
rtp@iaxs.net 24/7 address   rtp@daddy.static.iaxs.net while I am on-line
-------------------------------------------------------------------------------
If it wasn't for the dust, I'ld see Redmond, WA in my rearview mirror!
-------------------------------------------------------------------------------