积极预防 及时发现
快速响应 力保恢复
金山毒霸是国内广泛使用反病毒程序。金山毒霸2001的一个新功能称为邮件监控。可以在邮件被接收之前扫描...
发布时间:2002-04-01 信息来源:管理员

CNCVE编号:CNCVE-20020080 CVE编号: 安全级别:高 漏洞中文描述: 金山毒霸是国内广泛使用反病毒程序。金山毒霸2001的一个新功能称为邮件监控。可以在邮件被接收之前扫描是否包含病毒或危险程序。其原理是在本机建立一个pop3代理服务器,(用nc连到本机TCP/110可看到"+OK KAV2000 POP3 proxy ready!")。邮件客户端通过此代理服务器接收邮件,也就是说在邮件到达客户端程序之前就接受金山毒霸2002的扫描。但程序(mailmon.exe)并未设置IP地址过滤,任何主机都可进行连接,而且没有日志记录。那么,如果computerA运行了邮件监控,computerB只要把自己的邮件客户端pop3代理设置为computerA,就可以免费使用computerA的邮件监控功能。也可通过此代理功能不留痕迹地暴力破解邮箱密码。更糟糕的是mailmon.exe存在缓冲溢出问题,至少可以导致程序崩溃。更进一步的分析表明,可以通过巧妙构建的代码执行任何命令,或者获得一个远程shell。 漏洞英文描述: KAV9X.EXE is a widely used program against virus.KAV2001 has a new fuction,which is named mail Daemon.this new fuction allows user scan whether mail contains virus or dangerous program.first,the local host will establish a POP3 PROXY(if you connect to TCP port 110,you will see "+OK KAV2000 POP3 proxy ready!").The mail client receives mail through this proxy server,it means KAV2001 will scan the mail before it get to client.But the program(mailmon.exe)doesn't set IP filter,so any host can connected it without being logged.Then,if computerA is running mail daemon,computerB set computerA as its POP3 proxy server,it can use computerA's mail daemon freely,and it can get password through this proxy without being discovered.The worse thing is there is buffer overflow in mailmon.exe,it will cause program corrupted at least.More analysis show that attackers can excute arbitrary command or get a remote shell by constructing a malice code. 漏洞参考: http://www.whitecell.org/articles/mailmon.txt 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:缓冲区溢出