EmailDiscussions.com  

Go Back   EmailDiscussions.com > Discussions about Email Services > Email Comments, Questions and Miscellaneous
Register FAQ Members List Calendar Today's Posts
Stay in touch wirelessly

Email Comments, Questions and Miscellaneous Share your opinion of the email service you're using. Post general email questions and discussions that don't fit elsewhere.

Reply
 
Thread Tools
Old 12 May 2003, 06:23 AM   #1
elvey
The "e" in e-mail
 
Join Date: Jan 2002
Location: San Francisco
Posts: 2,458
slmail.com - was insecure! Multiple Vulnerabilities in SLWebMail

Wonder if FastMail or Runbox have had Typhon or other vulnerability assessments or vulnerability assessment tools run on them!


NGSSoftware Insight Security Research Advisory

Name: Multiple Vulnerabilities in SLWebMail
Systems Affected: SLWebMail 3 on Windows
Severity: High Risk
Vendor URL: http://www.slmail.com
Authors: David Litchfield (david@ngssoftware.com)
Mark Litchfield (mark@ngssoftware.com)
Date: 7th May 2003
Advisory URL: http://www.nextgenss.com/advisories/slwebmail-vulns.txt
Advisory number: #NISR07052003B

Description
***********
SLWebMail is a web based e-mail system that runs on top of Microsoft's
Internet Information Server. It is vulnerable to many different kinds of
issues, such as buffer overflows, arbitrary file access and physical path
revelation.

Details
*******

Buffer Overflows
****************
Many of the ISAPI DLL applications that form SLWebmail are vulnerable to
buffer overflow vulnerabilities. By passsing an overly long value for
certain parameters in the query string the overflows can be triggered.

Module: showlogin.dll
Parameter: Language

Module: recman.dll
Parameter: CompanyID

Module: admin.dll
Parameter: CompanyID

Module: globallogin.dll
Parameter: CompanyID

Abritrary File Access
*********************
ShowGodLog.dll can be accessed without requiring a remote user to
authenticate. This ISAPI application is used to show SLWebMail's log file.
However, by providing the path, relative or full, to any file that the
anonymous Internet account has read access to then access to the contents
can be gained, even outside of the web root.

Physical Path Revelation
************************
By making invalid requests to certain DLLs such as WebMailReq.dll the
complete physical path to the DLL is revealed. This information can be used
to help with other attacks.

Fix Information
***************
NGSSoftware alerted SLMail to these issues in February and an update has
been released. See http://www.slmail.com for more details.

A check for these issues has been added to Typhon, a comprehensive automated
vulnerability assessment tool of which more information is available from
the NGSSite: http://www.ngssoftware.com/

About NGSSoftware
*****************
NGSSoftware design, research and develop intelligent, advanced application
security assessment scanners. Based in the United Kingdom, NGSSoftware have
offices in the South of London and the East Coast of Scotland. NGSSoftware's
sister company NGSConsulting, offers best of breed security consulting
services, specialising in application, host and network security
assessments.

http://www.ngssoftware.com/
http://www.ngsconsulting.com/

Telephone +44 208 401 0070
Fax +44 208 401 0076

enquiries@ngssoftware.com
elvey is offline   Reply With Quote

Old 12 May 2003, 11:00 PM   #2
robert@fm
The "e" in e-mail
 
Join Date: Feb 2002
Location: London, UK
Posts: 4,681
Re: slmail.com - was insecure! Multiple Vulnerabilities in SLWebMail

Quote:
Originally posted by elvey
http://www.ngssoftware.com/
http://www.ngsconsulting.com/

Telephone +44 208 401 0070
Fax +44 208 401 0076
I'm not sure how much credence I, for one, would place in a security consultancy that can't even get its own telephone numbers right; whoever did the details for this one seems to have the common misapprehension that in 2000, 0171 changed to 0207 and 0181 to 0208.  In fact, what actually happened was that London was (after ten years) merged back into one telephone district (STD code 020) instead of two, and to make this possible, exchanges which formerly had the STD code 0171 had a 7 tacked onto them, and likewise exchanges in the former 0181 area; thus, +44 181 401 became +44 20 8401.

It doesn't make any difference from outside London, but try dialling "401 0070" from central London and see how far you get...
robert@fm is offline   Reply With Quote
Old 21 May 2003, 03:34 AM   #3
admiralu
Essential Contributor
 
Join Date: Jan 2002
Location: Camarillo, CA
Posts: 442
Cool

LOL
admiralu is offline   Reply With Quote
Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Forum Jump


All times are GMT +9. The time now is 06:14 PM.

 

Copyright EmailDiscussions.com 1998-2022. All Rights Reserved. Privacy Policy