<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=Content-Type content="text/html; charset=iso-8859-1">
<META content="MSHTML 6.00.2800.1106" name=GENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=#ffffff>
<DIV><FONT face=Arial
size=2>-=[--------------------------------ADVISORY----------------------<BR>-=[<BR>-=[
MailEnable Enterprise & Pro remote BoF<BR>-=[<BR>-=[ Author:
Expanders
[expanders@gmail.com]<BR>-=[
CorryL
[corryl80@gmail.com]<BR>-=[<BR>-=[
<A
href="http://www.x0n3-h3ck.org">www.x0n3-h3ck.org</A><BR>-=[------------------------------------------------------------------------</FONT></DIV>
<DIV> </DIV><FONT face=Arial size=2>
<DIV><BR>-=[+] Application: Mail Enable Imapd ( MEIMAP.exe
)<BR>-=[+] Version: (Enterprise <=
1.04)-(Professional <= 1.54)<BR>-=[+] Vendor's URL: <A
href="http://www.mailenable.com">www.mailenable.com</A><BR>-=[+]
Platform: Windows<BR>-=[+] Bug
type: Buffer overflow<BR>-=[+]
Exploitation: Remote/Local<BR>-=[-]<BR>-=[+]
Author: Expanders ~
expanders[at]gmail[dot]com ~<BR>-=[+]
Author:
CorryL ~ corryl80[at]gmail[dot]com ~<BR>-=[+]
Reference: <A
href="http://www.x0n3-h4ck.org">www.x0n3-h4ck.org</A></DIV>
<DIV> </DIV>
<DIV><BR>..::[ Descriprion ]::..</DIV>
<DIV> </DIV>
<DIV>MailEnable's mail server software provides a powerful, <BR>scalable hosted
messaging platform for Microsoft Windows. <BR>MailEnable offers stability,
unsurpassed flexibility and <BR>an extensive feature set which allows you to
provide<BR>cost-effective mail services.</DIV>
<DIV> </DIV>
<DIV><BR>..::[ Bug ]::..</DIV>
<DIV> </DIV>
<DIV>Imapd service is buffer overflow vulnerable at "A001 AUTHENTICATE
<buffer>" command.<BR>Passing a buffer greater than 1016 bytes will
overwrite ECX and EAX register allowing remote <BR>attacker to execute arbitraty
code on the vulnerable server.</DIV>
<DIV> </DIV>
<DIV><BR>..::[ Proof Of Concept ]::..</DIV>
<DIV> </DIV>
<DIV>A001 AUTHENTICATE "A"x1024</DIV>
<DIV> </DIV>
<DIV>..::[ Exploit ]::..</DIV>
<DIV> </DIV>
<DIV>Attached or:</DIV>
<DIV> </DIV>
<DIV><A
href="http://www.x0n3-h4ck.org/upload/x0n3-h4ck_MailEnable_Imapd.c">http://www.x0n3-h4ck.org/upload/x0n3-h4ck_MailEnable_Imapd.c</A></DIV>
<DIV> </DIV>
<DIV>..::[ Workaround ]::..</DIV>
<DIV> </DIV>
<DIV>There is no workaround</DIV>
<DIV> </DIV>
<DIV>..::[ Path or Fix ]::..</DIV>
<DIV> </DIV>
<DIV><A
href="http://www.mailenable.com/hotfix">http://www.mailenable.com/hotfix</A><BR><A
href="http://www.mailenable.com/hotfix/MEIMSM-HF050404.zip">http://www.mailenable.com/hotfix/MEIMSM-HF050404.zip</A></DIV>
<DIV> </DIV>
<DIV><BR>..::[ Disclousure Timeline ]::..</DIV>
<DIV> </DIV>
<DIV>[02/04/2005] - Vendor notification<BR>[03/04/2005] - Vendor
Response<BR>[03/04/2005] - Hotfix relased by vendor<BR>[05/04/2005] - Public
disclousure</FONT></DIV></BODY></HTML>