[22357] in bugtraq
Re: Lotus Domino DoS
daemon@ATHENA.MIT.EDU (3APA3A)
Tue Aug 21 13:31:09 2001
Date: Tue, 21 Aug 2001 12:47:35 +0400
From: 3APA3A <3APA3A@SECURITY.NNOV.RU>
Reply-To: 3APA3A <3APA3A@SECURITY.NNOV.RU>
Message-ID: <77256949073.20010821124735@sandy.ru>
To: Ian Gulliver <ian@orbz.org>
Cc: bugtraq@securityfocus.com
In-Reply-To: <20010820211932.F23908@penguinhosting.net>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Dear Ian Gulliver,
--21.08.2001 1:19, you wrote Lotus Domino DoS to bugtraq@securityfocus.com;
I> MAIL FROM:<bounce@[127.0.0.1]> RCPT
I> TO:<address@domain.com>
I> where domain.com is not local to the server in question,
I> the server attempts to bounce the message, and the bounce
I> goes into a loop, constantly being sent back to the same
I> server.
It was reported in vuln-dev list on May, 20 2000 by SMILER
<smiler@VXD.ORG> in same time with SMTP buffer overflow in
Lotus. I wonder why it's not patched yet.
http://www.security.nnov.ru/search/document.asp?docid=226
--
/3APA3A