what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

iMailv5.txt

iMailv5.txt
Posted Jan 4, 2000
Authored by Simon

On iMail Server 5.0 for Windows NT 4.0 SP 6a, a malicous user can read and send emails as any other user on the system. The issue lies in how iMail handles the creating of new email accounts, and how it stores them. Exploit instructions included.

tags | exploit
systems | windows
SHA-256 | cb49e1323d568f5b7d79148336aa88d62ecb3e572bce33f67d97c57bca63383e

iMailv5.txt

Change Mirror Download

0oooop
( / Six Toed
) / Security Advisory
(_<

Date: 2000, 03/01
Affected Software: iMail Server 5.0
Platform: Windows NT 4.0 SP 6a

*Problem*
A malicous user can read and send emails as any other user on
the system.

*How*
The issue lies in how iMail handles the creating of new email
accounts, and how it stores them.

When iMail is default installed all new email accounts are
stored in the same directory. So, the directory that held the
email
account for admin@domain.com would be stored in the same
directory as user@otherdomain.com.

*Exploit*
Now if user@otherdoamin.com has mail administration turned on,
user could create a new account under his domain
(otherdomain.com)
for admin, and since it iMail would store it in the same
directory as the as the admin@doamin.com account, they would
then become
one in the same. Thus allowing user@otherdomain.com to read ALL
incoming emails to admin@domain.com and all other 'admin' users
on
the system by sharing the same 'admin' folder. As you can
imagine, this could pose a serious risk to security.

*Fix*
When creating a new email account for a domain in iMail
Administrator, choose a custom path to save all accounts to.
Example:
D:\IMAIL\newdomain.com

As long as an administrator is keeping his eye on the ball this
little problem can be avoided.

*Notes*
I have not tested this problem on any earlier version of
iMail... Other versions are probably affected too. If you find
out they
are please email me.

*Shouts*
Lupus Gentry, Af8e 4f5, Logical Gambit, RandomS, knarph,
nulltone, Strick,
Ross, Everyone @ yak.net, and the girl who crushed Lupus's heat
today, this
means you Anna.

------------------------
Advisory By Simon(Says)
Six Toed 2000, 01/03
simonsays@ureach.com
VM. 1-877-815-7880 x916
------------------------

EOF


________________________________________________
Get your own "800" number - Free
Free voicemail, fax, email, and a lot more
http://www.ureach.com/reg/tag
--_uReach_com_26916734994695633528830xxx_--

Login or Register to add favorites

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    15 Files
  • 2
    Aug 2nd
    22 Files
  • 3
    Aug 3rd
    0 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    15 Files
  • 6
    Aug 6th
    11 Files
  • 7
    Aug 7th
    43 Files
  • 8
    Aug 8th
    42 Files
  • 9
    Aug 9th
    36 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    27 Files
  • 13
    Aug 13th
    18 Files
  • 14
    Aug 14th
    50 Files
  • 15
    Aug 15th
    0 Files
  • 16
    Aug 16th
    0 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    0 Files
  • 20
    Aug 20th
    0 Files
  • 21
    Aug 21st
    0 Files
  • 22
    Aug 22nd
    0 Files
  • 23
    Aug 23rd
    0 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close