Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Metainfo MetaIP and Sendmail Vulnerabilities

Identifying a victim:
For sendmail, telneting to port 25 will yield a banner stating 'Sendmail
2.0/
2.5 (Build xxxx)', which lets you know they're running MetaInfo Sendmail
(v2.5 includes MetaInfo's name in the banner).
For MetaIP, if remote administration is enabled, telneting to port 2040
(default) will give you a prompt to the effect of 'V3.1'.

Of course, the default Java config port of 2040, and the web UI ports
of 5000 and 5001 are user-definable; so it is possible to have these
services
running and not on these particular ports. A thorough port scan would
resolve that issue.







 

Privacy Statement
Copyright 2009, SecurityFocus