81
Stalker Internet Mail Server 1.6 buffer overflow
SMTP
2004/03/23
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
2004/11/13
1.2
Corrected the plugin structure and added the accuracy values in 1.2
tcp
25
open|sleep|close|pattern_exists 220 *Stalker Internet Mail Server V.1.6 is ready.*
90
This plugin was written with the ATK Attack Editor.
http://www.securityfocus.com/archive/1/8951
Stalker Internet Mail Server 1.6
Stalker Internet Mail Server 1.7 and newer
Buffer Overflow
The Stalker Internet Mail Server is a small Mail Transfer Agent. It has been discovered that a buffer overflow can be exploitet sending several hundred bytes of data as hostname with the HELO command. It has been reported that this will cause to crash the server. But it may be possible to run arbritrary code with the server privileges.
There is a new software version available. You should upgrade your system. Limit unwanted connections and communications with firewalling.
1 hour
Yes
http://www.securityfocus.com/bid/62/exploit/
Yes
Yes
High
8
8
9
8
CAN-1999-1504
62
Hacking Exposed: Network Security Secrets & Solutions, Stuart McClure, Joel Scambray and George Kurtz, February 25, 2003, 4th Edition, McGraw-Hill Osborne Media, ISBN 0072227427
http://www.computec.ch