TCLUG Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Security holes in IMAP



I've heard that there were security holes in IMAP -- this news story
recently ran on ZDNet mentioning a worm being used to exploit them.

http://www.zdnet.com/zdnn/stories/news/0,4586,2169798,00.html

  The reason I'm interested is that recently the ipfwadm setup I have on my
home Linux server (modified from Tom Cross' "slatch" scripts) registered
unauthorized access attempts on the IMAP port -- two within a week, in fact.

  Does anybody know if this is a concern for more recent versions of IMAP?
The article says it mostly affects users of RedHat 5.0, which strikes me as
FUDdishly vague.  Also, it doesn't mention exactly what it is this worm
*does*, or how to tell if your system might have been infected.