what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

0x36.smartmax

0x36.smartmax
Posted May 23, 2003
Authored by Mark Litchfield, Matrix

Mailmax Version 5 has a buffer overflow condition in its IMAP4 server that can cause the service to stop responding and allows a remote attacker to overwrite the exception handler on the stack. Doing this could allow arbitrary code execution as the SYSTEM user.

tags | advisory, remote, overflow, arbitrary, code execution
SHA-256 | 77a4c3f55a95ea74b2243674c8580202f49806febff62a751e26591ada15dac5

0x36.smartmax

Change Mirror Download
    ____        ,_____   __ 
/ \ |___ / / / Buffer Overflow Vulnerability
( /\ ) / / / / __ Found in MailMax Version 5
( \/ ) \ / ,_\ \ ( ( \ \ http://www.smartmax.com
\____/ / \ |____\ \_\_/_/ matrix at 0x36.org
ooOOooOOooOOooOOooOOooOOooOOooOOooOOooOOooOOooOOooOOooOOooOOooOOooOOooOOooOOoo


<[SUMMARY]>-------------------------------------------------------------------
This is a scalable e-mail server that supports SMTP, IMAP4 and POP3 protocols.
Its TCP/IP GUI allows server administration from any Internet connected server.
The Web Admin module allows you to define domain administrators so they can
Maintain their own accounts. It also provides anti-spamming options.

The problem is a Buffer Overflow in the IMAP4 protocol, within the
IMAP4rev1 SmartMax IMAPMax 5, causing the service to stop responding
and we can actually overwrite the exception handler on the stack allowing
a system compromise with code execution running as SYSTEM.

<[AFFECTED SYSTEMS]>----------------------------------------------------------
Vulnerable systems:
* IMAP4rev1 SmartMax IMAPMax 5 (5.0.10.8)

Immune systems:
* IMAP4rev1 SmartMax IMAPMax 5.5

<[SEVERITY]>------------------------------------------------------------------
Medium/High - An attacker is able to cause a DoS attack on the IMAP protocol
The reason this is also a medium is that and attacker has to have
a login on the system to conduct this attack.
And we can actually overwrite the exception handler on the stack
allowing a system compromise with code execution running as SYSTEM

<[DESCRIPTION OF WHAT THE VULNERABILITY IS]>----------------------------------
The Vulnerability is a Buffer Overflow in the IMAP4rev1 SmartMax IMAPMax 5
When a malicious attacker sends a large amount into the SELECT command.
The buffer will overflow. Sending to many bytes into the buffer will cause the
server to reject the request and nothing will happend.


The following transcript demonstrates a sample exploitation of the
vulnerabilities

--------[ transcript ]-------
nc infowarfare.dk 143
* OK IMAP4rev1 SmartMax IMAPMax 5 Ready
0000 CAPABILITY
* CAPABILITY IMAP4rev1
0000 OK CAPABILITY completed
0001 LOGIN "RealUser@infowarfare.dk" "HereIsMyPassword"
0001 OK User authenticated.
0002 SELECT "aaa...[256]...aaaa"
--------[ transcript ]-------

When this attack is used there will pop-up a message box on the server, with
the text "Buffer overrun detected! - Program: <PATH>\IMAPMax.exe" at this time
the service shuts down, and has to be restarted manually, from the service
manager.


<[DETECTION]>----------------------------------------------------------------
IMAP4rev1 SmartMax IMAPMax 5 is vulnerable to the above-described attacks.
Earlier versions may be susceptible as well. To determine if a specific
implementation is vulnerable, experiment by following the above transcript.


<[WORK AROUNDS]>-------------------------------------------------------------
The only work around if you do not want to update your system is to disable
the IMAP service, else i would higly recommend updating to version 5.5 of
MailMAX


<[VENDOR RESPONSE]>----------------------------------------------------------
it's fixed in 5.5, to be released by May 10th.
5.5 is the update to 5.0. It is a free upgrade for owners of 5.0.
Regards,
Eric Weber


<[DISCLOSURE TIMELINE]>------------------------------------------------------
11/04/2003 Recived a mail from Mark Litchfield, about this could be vulnerable
by sending a larger buffer. So credits should also go to Mark
15/04/2003 Made an analysis and found the vulnerability
28/04/2003 Reported the vulnerability to Vendor (support-at-smartmax.com)
02/05/2003 Recived responce from Vendor
17/05/2003 Public Disclosure.


<[ADDITIONAL INFORMATION]>---------------------------------------------------
The vulnerability was discovered and reported by <Matrix at 0x36.org>


<[DISCLAIMER]>---------------------------------------------------------------
The information in this bulletin is provided "AS IS" without warranty of any
kind. In no event shall we be liable for any damages whatsoever including
direct, indirect, incidental, consequential, loss of business profits or
special damages.
Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    8 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    18 Files
  • 19
    Nov 19th
    7 Files
  • 20
    Nov 20th
    13 Files
  • 21
    Nov 21st
    6 Files
  • 22
    Nov 22nd
    48 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    60 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    44 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close