88
Emumail WebMail detection
CGI
2004/03/23
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
2004/11/14
2.0
Corrected the plugin structure and added the accuracy values in 1.3. Improved the pattern matching and introduced the plugin changelog in 2.0
tcp
80
open|send GET /emumail.fcgi HTTP/1.0\n\n|sleep|close|pattern_exists HTTP/#.# ### *Powered by EMU Webmail*
95
This plugin was written with the ATK Attack Editor.
Emumail EMU WebMail
Other web mail solutions
Configuration
The host is running Emumail EMU WebMail which contained many nasty security vulnerabilities in older versions.
Try to verify the existence of the known flaws. If they are present, do an upgrade to the latest version or use an alternative product.
1 hour
Yes
http://www.securityfocus.com/bid/9861/exploit/
Yes
Yes
Low
5
8
5
5
Medium
Nessus is able to do some Emumail WebMail checks.
9861
12095
Hacking Exposed: Network Security Secrets & Solutions, Stuart McClure, Joel Scambray and George Kurtz, February 25, 2003, 4th Edition, McGraw-Hill Osborne Media, ISBN 0072227427
http://www.computec.ch