pen-test
[Top] [All Lists]

Re: WASC-Announcement: MX Injection - Capturing and Exploiting Hidden Ma

To: Thiago Zaninotti <thiago@zaninotti.net>
Subject: Re: WASC-Announcement: MX Injection - Capturing and Exploiting Hidden Mail Servers By Vicente Aguilera Diaz
From: Joseph McCray <joe@learnsecurityonline.com>
Date: Mon, 18 Dec 2006 09:57:30 -0500
Cc: Chris Gates <chris@learnsecurityonline.com>, Marcelo Leão Caffaro <marcelocaffaro@gmail.com>, pen-test@securityfocus.com
Delivered-to: sp-com-lists@consult.net
Delivered-to: pentest-list2@consult.net
Delivered-to: mailing list pen-test@securityfocus.com
Delivered-to: moderator for pen-test@securityfocus.com
In-reply-to: <2757cb890612161825m2b47ee7fp1f842090bf592888@mail.gmail.com>
List-help: <mailto:pen-test-help@securityfocus.com>
List-id: <pen-test.list-id.securityfocus.com>
List-post: <mailto:pen-test@securityfocus.com>
List-subscribe: <mailto:pen-test-subscribe@securityfocus.com>
List-unsubscribe: <mailto:pen-test-unsubscribe@securityfocus.com>
Mailing-list: contact pen-test-help@securityfocus.com; run by ezmlm
Organization: Learn Security Online
References: <20061211155443.2671.qmail@cgisecurity.net> <458180c0.5f96de1e.7b7d.fffffc1c@mx.google.com> <2757cb890612161825m2b47ee7fp1f842090bf592888@mail.gmail.com>
Reply-to: joe@learnsecurityonline.com
Resent-date: Tue, 19 Dec 2006 21:10:00 -0700 (MST)
Resent-from: pen-test-return-1078483272@securityfocus.com
Resent-message-id: <20061220041000.B7911238AB0@outgoing3.securityfocus.com>
Resent-sender: listbounce@securityfocus.com
Sender: listbounce@securityfocus.com
Thiago, there is a great bit of info in the MX Injection paper has been
discussed in other places around the web and even implemented in a few
tools, but I don't think Marcelo was trying to say that EVERYTHING in
the entire paper was new and discovered by him alone.

I used his paper in a class I was teaching last week. I thought it was
relevant to showing how penetration testing is moving away from service
exploitation to web app, database and client side exploitation and it
drives home the point of webmail being a valid means into mail servers
you not otherwise have access to. Hint hint Marcelo - add some Outlook
Web Access content into this paper and it would be awesome! :)

Also, SMTP injection was only part of what was discussed in his paper
(requiring a valid account if I recall). I really liked the paper
because it covered IMAP injection, and some nice little IMAP enumeration
commands. Gave me some ideas for things I'd like to try in my next
audit. All in all I thought it was pretty good.


-- 
Joe McCray
Toll Free:  1-866-892-2132
Email:      joe@learnsecurityonline.com
Web:        https://www.learnsecurityonline.com


Learn Security Online, Inc.

* Security Games        * Simulators
* Challenge Servers     * Courses
* Hacking Competitions  * Hacklab Access


On Sun, 2006-12-17 at 00:25 -0200, Thiago Zaninotti wrote:
> Hi Marcelo,
> 
> Part of this technique is not new and has been part of N-Stalker Web
> Application Security Scanner for a long time (SMTP Injection).
> 
> There are also papers that would go further on exploiting specific
> frameworks such as CDONTS.
> 
> For more information, see N-Stalker Free Edition tool at
> www.nstalker.com/free-edition
> 
> Best regards,

Attachment: signature.asc
Description: This is a digitally signed message part

<Prev in Thread] Current Thread [Next in Thread>