Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Incidents
[Top] [All Lists]

Re: Possible Mail server compromise ?

Subject: Re: Possible Mail server compromise ?
Date: Wed, 20 Feb 2008 20:25:51 +0100
Dear Bob,

I don't want to start a flame war, let's keep the information relevant
and on topic, as such I'd like
to comment on things relevant to the general public, everything else
is private mail. :) ok?

It goes without saying that patching does not protect against zero day
exploits.
:)

I don't understand what you are saying.  I am assuming that the nruns.com
product is scanning for viruses in email.
Hmm, I am not sure you (or I) got it right, but apparently they don't parse
the data. So basically if they don't parse it they are a lot less vulnerable
to remote attacks, agree?

Thus, the data (the email)
can be manipulated by the attacker.
See above, as I understand it, there is no parsing involved a part
from your normal FROM etc headers.
Attachments that normally contain the payloads (read lots of formats)
are usually

"No-Parsing paradigma"?  Paradigma isn't even a word (according to
www.merriam-webster.com).
You are referring to a typo instead of commenting on my concern,  lets
keep the mails relevant
for the general public, if your comment was sincere : you should
lookup "paradigm"

Our product (and to various degrees others, such as raw ClamAV) also run
in a "sealed" environment such as a separate UID, chroot'ed, etc.
I beg to differ, chroot is by no means a "sealed" environment. There
are lots of ways to break out of it...

No, ClamAV would not be vulnerable to this ...
What I posted here was an exploit against Clamav
http://milw0rm.com/exploits/4761

Regards,
Faas.M.Mathiasen

<Prev in Thread] Current Thread [Next in Thread>