223 MailEnable SMTP Connector Service 1.x DNS Lookup denial of service SMTP 2004/09/14 Marc Ruef marc dot ruef at computec dot ch http://www.computec.ch computec.ch Marc Ruef marc dot ruef at computec dot ch http://www.computec.ch computec.ch 2004/11/13 1.1 Corrected the plugin structure and added the accuracy values in 1.1 tcp 25 open|sleep|close|pattern_exists 220 *Enable*1.[0-6]* OR 220 *Enable*1.7.[0-1]* OR 220 *Enable*0.#* OR 220 *Enable*1.[0-2]* 80 This ATK plugin is inspired by the Nessus plugin. The Standard Edition seems to format version as "1.71--" (for 1.71) while Professional Edition formats it like "0-1.2-" (for 1.2). info at mailenable dot com http://www.mailenable.com MailEnable 2004/11/09 http://www.mailenable.com/hotfix/ MailEnable SMTP Connector Service 1.x Fixed MailEnable SMTP Connector Service 1.x or other solutions Denial Of Service The target system is running MailEnable SMTP Connector Service 1.x. There is a denial of service vulnerability in the DNS Lookup. An attacker is able to crash the service if more than 100 requests for MX records are sent. Apply the DNS Lookup hotfix from http://www.mailenable.com/hotfix/ or upgrade the software to the latest release. To make it harder to find the server the daemon could be configured to listen at another port (e.g. 8025). Try to prevent unwanted connection attempts by filtering traffic with firewalling. Alternation of the application banner can confuse an attacker and let him determine the wrong software. Approx. 30 minutes Yes http://www.securityfocus.com/bid/5261/exploit/ Yes No Medium 3 6 8 5 Low Nessus is able to do the same check, 11144 9789 14712 Hacking Exposed: Network Security Secrets & Solutions, Stuart McClure, Joel Scambray and George Kurtz, February 25, 2003, 4th Edition, McGraw-Hill Osborne Media, ISBN 0072227427 http://www.mailenable.com