what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

VIGILANTE-2000008.txt

VIGILANTE-2000008.txt
Posted Sep 6, 2000
Authored by Vigilante | Site vigilante.com

Vigilante Advisory #8 - NTMail Configuration Service v5 & v6 denial of service. The web configuration running on TCP port 8000 does not flush incomplete HTTP requests, and thus it is possible to use up all the server ressources within a very short time.

tags | exploit, web, denial of service, tcp
SHA-256 | c9fec19beb463e9c88ed288d26e1bc526386517c5982cb2f718dc275c18ea22b

VIGILANTE-2000008.txt

Change Mirror Download
NTMail Configuration Service DoS

Advisory Code: VIGILANTE-2000008

Release Date:
September 4, 2000

Systems Affected:
- NTMail V5 Alpha Processor
- NTMail V5 Intel Processor
- NTMail V6 Alpha Processor
- NTMail V6 Intel Processor

THE PROBLEM
The web configuration running on TCP port 8000 does not flush incomplete
HTTP requests, and thus it is possible to use up all the server ressources
within a very short time. During testing the CPU usage stayed around 90-99%
and within 2 minutes the www.exe service had consumed more than 250MB of
memory. An attack might result in the service crashing, when the system hits
the maximum pagefile size.

Vendor Status:
Gordano was contacted on the 19th of August (Saturday) and a reply was
received on the 21st of August. On The 22nd of August we received a fix,
which appears to fix the problem.

Fix (quote from the vendor):
"Gordano Limited, developers of the award winning mail server NTMail, are
pleased to have worked with Vigilante.com to secure their product
and protect their customers from a potential DoS exploit."

NTMail V5 Alpha Processor fix URL:
ftp://ftp.gordano.com/ntmail5/hotfixes/ntmail5g_alpha_20000830.zip

NTMail V5 Intel Processor fix URL:
ftp://ftp.gordano.com/ntmail5/hotfixes/ntmail5g_intel_20000830.zip

NTMail V6 Alpha Processor fix URL:
ftp://ftp.gordano.com/ntmail6/hotfixes/ntmail6_alpha_20000830.zip

NTMail V6 Intel Processor fix URL:
ftp://ftp.gordano.com/ntmail6/hotfixes/ntmail6_intel_20000830.zip


Vendor URL: http://www.gordano.com/
Product URL: http://www.ntmail.co.uk/
Copyright VIGILANTe 2000-08-19

Disclaimer:
The information within this document may change without notice. Use of
this information constitutes acceptance for use in an AS IS
condition. There are NO warranties with regard to this information.
In no event shall the author be liable for any consequences whatsoever
arising out of or in connection with the use or spread of this
information. Any use of this information lays within the user's
responsibility.

Feedback:
Please send suggestions, updates, and comments to:

VIGILANTe
mailto: swat@vigilante.com
http://www.vigilante.com

Login or Register to add favorites

File Archive:

October 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Oct 1st
    39 Files
  • 2
    Oct 2nd
    23 Files
  • 3
    Oct 3rd
    18 Files
  • 4
    Oct 4th
    20 Files
  • 5
    Oct 5th
    0 Files
  • 6
    Oct 6th
    0 Files
  • 7
    Oct 7th
    17 Files
  • 8
    Oct 8th
    66 Files
  • 9
    Oct 9th
    25 Files
  • 10
    Oct 10th
    20 Files
  • 11
    Oct 11th
    21 Files
  • 12
    Oct 12th
    0 Files
  • 13
    Oct 13th
    0 Files
  • 14
    Oct 14th
    14 Files
  • 15
    Oct 15th
    49 Files
  • 16
    Oct 16th
    28 Files
  • 17
    Oct 17th
    23 Files
  • 18
    Oct 18th
    10 Files
  • 19
    Oct 19th
    0 Files
  • 20
    Oct 20th
    0 Files
  • 21
    Oct 21st
    5 Files
  • 22
    Oct 22nd
    12 Files
  • 23
    Oct 23rd
    23 Files
  • 24
    Oct 24th
    9 Files
  • 25
    Oct 25th
    0 Files
  • 26
    Oct 26th
    0 Files
  • 27
    Oct 27th
    0 Files
  • 28
    Oct 28th
    0 Files
  • 29
    Oct 29th
    0 Files
  • 30
    Oct 30th
    0 Files
  • 31
    Oct 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close