what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

TTG0602.txt

TTG0602.txt
Posted Sep 7, 2006
Authored by TTG | Site teklow.com

Alt-N WebAdmin version 3.2.5 running with MDaemon version 9.0.6 suffers from a flaw that allows Domain administrators within the default domain the ability to take over the MDaemon system account.

tags | advisory
SHA-256 | 49daca546bd5669665982a276cd4a7d2289a0ff3b5a1c24e3ce157138c26e127

TTG0602.txt

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


TTG0602 - Alt-N WebAdmin MDaemon Account Hijacking

RELEASE DATE:
September 4, 2006

VENDOR:
Alt-N Technologies ( http://www.altn.com )

VULNERABLE:
Tested on Alt-N WebAdmin v3.2.5 running
with MDaemon v9.0.6, earlier versions are
suspected vulnerable as well

SEVERITY:
Domain administrators within the default domain
can take over the "MDaemon" system account, which
could lead to compromise of sensitive data

OS:
Microsoft Windows XP/2000/2003



SUMMARY

WebAdmin is a remote administration utility which allows administrators to
manage Alt-N's MDaemon, RelayFax and WorldClient products. Recently this
has become a standard module for the company's MDaemon mail server, altough
it remains available independently as well.

It is possible for a domain administrator within the default domain of a
MDaemon server to gain access to the server's "MDaemon" account through the
WebAdmin. This is the account which processes remote server and mailinglist
commands, which are authenticated by putting a user's email address and
password in the subject field of a message.

By taking over this account and enabling mail access to it a malicious
domain administrator could gain access to the system queue, the contents of
which are by default only stored on disk and not accessible.

It is important to note that this queue processes the messages for all
domains on the server, not just the local one.



DETAILS

Within the MDaemon structure, domain administrators are users which are
allowed to manage accounts for a specific domain on the server. While the
"MDaemon" account is not available or even visible for modification in the
WebAdmin interface, it's details can be accessed through sending a specially
constructed url to the useredit_account.wdm module.

Access to it's settings are still restricted when called in this way.
However,
it is possible to rename the mailbox to which this account directs it's
queue.
By now creating a new account with the details of original MDaemon account
and enabling mail access to it, the messages destined for the server account
can be read through a regular mail interface while they're stored until
processed.

This account will now also be recognized as the system account by the server
and the original MDaemon user, now just a regular account, can be deleted by
the domain administrator to cover his tracks.



IMPACT

The impact of this vulnerability in a small environment using only trusted
administrators is low. In larger environments were one to trust on WebAdmin's
user restrictions the impact of mentioned problems is larger, as they could
allow further compromise of accounts on any domain, not just the local one,
on the server.



FIX

WebAdmin v3.2.5 was released on August 18 in response to earlier reported
vulnerabilities(1). In testing, it was found that while previous issues were
fixed, this version still did not completely curtail access to the MDaemon
account for some users.

The vendor was notified of this on August 24th and WebAdmin v3.2.6(2) was
issued on August 30th. This update has been confirmed to fix this matter by
ourselves on September 1st and we waited until after the weekend to release
this to facilitate updating.



REFERENCES

(1) TTG0601 - Alt-N WebAdmin Multiple Vulnerabilities
http://www.teklow.com/advisories/TTG0601.txt

(2) WebAdmin Server v3.2.6 Release Notes
http://files.altn.com/WebAdmin/Release/RelNotes_en.txt

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (MingW32)

iD8DBQFE/If1XSyYXTPz6J0RAnUEAJ44uUgIr1Ocnl09wbPFx5ulZhVhxACeOi4g
ODlCA1WIwRNGnLg+d9LGZtU=
=Wame
-----END PGP SIGNATURE-----


Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    0 Files
  • 9
    Sep 9th
    0 Files
  • 10
    Sep 10th
    0 Files
  • 11
    Sep 11th
    0 Files
  • 12
    Sep 12th
    0 Files
  • 13
    Sep 13th
    0 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    0 Files
  • 17
    Sep 17th
    0 Files
  • 18
    Sep 18th
    0 Files
  • 19
    Sep 19th
    0 Files
  • 20
    Sep 20th
    0 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close