[28306] in bugtraq

home help back first fref pref prev next nref lref last post

junkbuster 2.0-1 proxy relaying spam

daemon@ATHENA.MIT.EDU (Andrew Daviel)
Mon Dec 23 15:54:16 2002

Date: Mon, 23 Dec 2002 02:11:41 -0800 (PST)
From: Andrew Daviel <andrew@andrew.triumf.ca>
To: BUGTRAQ@securityfocus.com
Message-ID: <Pine.LNX.4.44.0212230140170.32411-100000@andrew.triumf.ca>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII


I just found a "junkbuster" proxy on a RedHat 6.2 machine
being used to relay spam - a bit ironic, considering the
intention of the program.

This is junkbuster-2.0-1 installed as part of a 
"complete install" on RedHat 6.2.
It seems that the default install sets no ACL, no logging,
and starts the program on boot.

This is not the buffer overflow reported in 1998. It is
a simple use of the HTTP CONNECT method similar to the Korean
school Apache proxies 

The default for junkbuster 2.0-2 is to listen on localhost only,
so modern installs should be safe.

-- 
Andrew Daviel, TRIUMF, Canada
Tel. +1 (604) 222-7376
security@triumf.ca



home help back first fref pref prev next nref lref last post