Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Security Incidents: Re: iPlanet Server vulnerable to HTTP TCP HEAD Attack

Re: iPlanet Server vulnerable to HTTP TCP HEAD Attack

From: Paul Cardon <paul_at_moquijo.com>
Date: Wed, 10 Apr 2002 19:18:42 -0400

Mendoza Bazan, Luis - (Per) wrote:
> Hi,
>
> I have an iPlanet server that work as email server. This server has the
> following services enabled: SMTP, POP3 and HTTP. We detect the evidence that
> is in the files attached. If you know some advice or workaround about this,
> it will be welcome.
> We are searching in Sun some info but cannot find it.

Well Luis, it looks like you have a publicly accessible proxy server and
somebody is attempting to use it to get their porn. I would recommend
that you either disable the proxy or configure access controls on it
that restricts its use. You should also be aware that when you post
sniffer traces the IP address a.b.c.55 that you were trying to obfuscate
shows up in there in hexadecimal (c80e f137) unless you also obfuscate
it. I can't imagine that your customer or employer would be happy that
you have advertised that information on a public mailing list.

-paul

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com
Received on Apr 11 2002

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos