195
IlohaMail detection
CGI
2004/09/09
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
2004/11/13
1.1
Corrected the plugin structure and added the accuracy values in 1.1
tcp
80
open|send GET /index.php HTTP/1.0\n\n|sleep|close|pattern_exists HTTP/#.# ### *IlohaMail*
95
Check is inspired by the Nessus plugin. The sub-directories /webmail, /ilohamail, /IlohaMail and /mail should be checked additionally.
George A. Theall
IlohaMail
Other solutions
Configuration
The remote host is running the IlohaMail suite. This is a webmail application that is based on a stock build of PHP and that does not require either a database or a separate IMAP library.
You should install or upgrade the software to the latest version to prevent the exploitation of known vulnerabilities. See http://www.ilohamail.org for more details. Also limit unwanted connections and communications with firewalling if possible.
Approx. 30 minutes
Yes
Yes
Yes
Low
2
8
3
4
Low
Nessus is able to do the same check with different directories.
14629
Hacking Exposed: Network Security Secrets & Solutions, Stuart McClure, Joel Scambray and George Kurtz, February 25, 2003, 4th Edition, McGraw-Hill Osborne Media, ISBN 0072227427
http://www.computec.ch