Secunia Security Advisory - A weakness has been reported in Intellipeer Email Server, which can be exploited by malicious people to determine valid usernames.
6b1eed1a75a9bc5799bc53c05fdbe94b374c823f10ca42264b281dbb3c8dab1e
TITLE:
Intellipeer Email Server User Account Enumeration Weakness
SECUNIA ADVISORY ID:
SA12661
VERIFY ADVISORY:
http://secunia.com/advisories/12661/
CRITICAL:
Not critical
IMPACT:
Exposure of system information
WHERE:
>From local network
SOFTWARE:
Intellipeer Email Server 1.x
http://secunia.com/product/3957/
DESCRIPTION:
Ziv Kamir has reported a weakness in Intellipeer Email Server, which
can be exploited by malicious people to determine valid usernames.
The problem is that different error messages are returned by the POP3
service depending on whether an unsuccessful login attempt is
performed with a valid or invalid username.
The weakness has been reported in version 1.01. Other versions may
also be affected.
SOLUTION:
Restrict access to the POP3 service.
Use strong passwords.
PROVIDED AND/OR DISCOVERED BY:
Ziv Kamir
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------