Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Possible Mail server compromise ? |
|---|---|
| Date: | Wed, 20 Feb 2008 20:25:51 +0100 |
Dear Bob, I don't want to start a flame war, let's keep the information relevant and on topic, as such I'd like to comment on things relevant to the general public, everything else is private mail. :) ok?
It goes without saying that patching does not protect against zero day exploits.
:)
I don't understand what you are saying. I am assuming that the nruns.com product is scanning for viruses in email.
Hmm, I am not sure you (or I) got it right, but apparently they don't parse the data. So basically if they don't parse it they are a lot less vulnerable to remote attacks, agree?
Thus, the data (the email) can be manipulated by the attacker.
See above, as I understand it, there is no parsing involved a part from your normal FROM etc headers. Attachments that normally contain the payloads (read lots of formats) are usually
"No-Parsing paradigma"? Paradigma isn't even a word (according to www.merriam-webster.com).
You are referring to a typo instead of commenting on my concern, lets keep the mails relevant for the general public, if your comment was sincere : you should lookup "paradigm"
Our product (and to various degrees others, such as raw ClamAV) also run in a "sealed" environment such as a separate UID, chroot'ed, etc.
I beg to differ, chroot is by no means a "sealed" environment. There are lots of ways to break out of it...
No, ClamAV would not be vulnerable to this ...
What I posted here was an exploit against Clamav http://milw0rm.com/exploits/4761 Regards, Faas.M.Mathiasen
| Previous by Date: | Re: Possible Mail server compromise ?, Faas M. Mathiasen |
|---|---|
| Next by Date: | Re: Possible Mail server compromise ?, Peter Kosinar |
| Previous by Thread: | Re: Possible Mail server compromise ?, Bob Toxen |
| Next by Thread: | Re: Possible Mail server compromise ?, Eygene Ryabinkin |
| Indexes: | [Date] [Thread] [Top] [All Lists] |