Click here to get back home

Exploit in IIS to send spam?

 HomeNewsGroups | Search

microsoft.public.windows.server.security - Supporting MS Windows network? Read here before it's too late! 

get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Exploit in IIS to send spam? Marc Hoffman 01-05-2006
Posted by Marc Hoffman on January 5, 2006, 12:02 pm
Please log in for more thread options
Hi All...

Without being too specific here for security reasons, does anyone know if a
security vulnerability in IIS 6's SMTP service that would allow an attacker
to relay spam via an online web form?


Posted by Roger Abell [MVP] on January 5, 2006, 1:31 pm
Please log in for more thread options
via an online form ???
only if the form is really poorly written

I can envision a form that allows one to enter every field
needed for an email and that just passes that along.
Then clearly one can automate something that just does
http posts over and over with as long of a to list as the
form allows.

That is a programming error however, not an issue in
the IIS implementation of SMTP, nor for that matter in
the MS implementation of CDO if that is what the form
used.

show/hide quoted text



Posted by sorcerdon on January 5, 2006, 6:27 pm
Please log in for more thread options
What exactly is the problem?


Posted by Roger Abell [MVP] on January 5, 2006, 11:42 pm
Please log in for more thread options
show/hide quoted text
I have none.
OP may be confusing misconfigured SMTP being used
as an open relay or such with use of their page forms.



Similar ThreadsPosted
Net send over different domains November 21, 2008, 7:50 am
Send Client Certificate February 18, 2008, 10:54 am
File Screen only send out email once September 6, 2007, 4:32 am
Email program won't send in Windows 2003 - Queue_Manager December 8, 2005, 2:02 pm
POP3 Spam with server name October 25, 2006, 8:59 pm
Spam monitoring yahoo details June 24, 2005, 12:27 pm
Disinfecting Win2kAS Spam Zombie December 12, 2005, 4:47 am
Clustered Exchange AV + SPAM tools January 19, 2007, 11:03 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Driving a better car - Fuelzilla.com

Cabling site for homeowners and pros alike - Cabling-Design.com

Friends:

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap
Privacy Policy