Re: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-11-02 Thread Don Brown
Wednesday, November 1, 2006, 1:21:54 PM, Matt [EMAIL PROTECTED] wrote: M Len, et. al, M IMail 8.x does not support Auth-only on any port, so it is not possible M to just simply work around the vulnerability in this way. M [Snip] M Matt According to this KB article, Auth on 587 is supported for

Re: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-11-02 Thread Darin Cox
Yes, AUTH is supported, but so is non-AUTH. So, therefore, AUTH-Only is not supported. Darin. - Original Message - From: Don Brown [EMAIL PROTECTED] To: Imail_Forum@list.ipswitch.com Sent: Thursday, November 02, 2006 10:35 AM Subject: Re: [IMail Forum] Update for SMTP vulnerability

Re: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-11-02 Thread Len Conrad
AUTH-Only is not supported. on port 587? When I've tested port 587, it fails any SMTP commands except EHLO and AUTH, if AUTH hasn't been successfully executed. Len To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive:

Re: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-11-02 Thread Darin Cox
Well..my bad. I thought that wasn't added until 2006. Darin. - Original Message - From: Len Conrad [EMAIL PROTECTED] To: Imail_Forum@list.ipswitch.com Sent: Thursday, November 02, 2006 10:52 AM Subject: Re: [IMail Forum] Update for SMTP vulnerability in 8.22 AUTH-Only

RE: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-11-01 Thread Mike Callahan
: RE: [IMail Forum] Update for SMTP vulnerability in 8.22 ASSP, IMGATE, , Barracuda and Alligate all sit in front of the mail server and act as a gateway. If you keep your mail server otherwise firewalled and have one of these products out in front then the vulnerability is mitigated (from external

RE: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-11-01 Thread Mike Callahan
Of Chris Moody Sent: Friday, October 27, 2006 12:31 PM To: Imail_Forum@list.ipswitch.com Subject: RE: [IMail Forum] Update for SMTP vulnerability in 8.22 ASSP, IMGATE, , Barracuda and Alligate all sit in front of the mail server and act as a gateway. If you keep your mail server otherwise firewalled

RE: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-11-01 Thread Chris Moody
To: Imail_Forum@list.ipswitch.com Subject: RE: [IMail Forum] Update for SMTP vulnerability in 8.22 ASSP, IMGATE, , Barracuda and Alligate all sit in front of the mail server and act as a gateway. If you keep your mail server otherwise firewalled and have one of these products out in front

RE: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-11-01 Thread Chris Moody
S'Okay. :) -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Mike Callahan Sent: Wednesday, November 01, 2006 10:58 AM To: Imail_Forum@list.ipswitch.com Subject: RE: [IMail Forum] Update for SMTP vulnerability in 8.22 Oops, never mind. I misread

RE: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-11-01 Thread Len Conrad
Just out of curiosity, what is the benefit of running ASSP, IMGATE, Barracuda, and Alligate all in front of your mail system? I have used most of these products individually in front a several different types of mail servers, and it would seem to me there would be little if any benefit

Re: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-11-01 Thread Matt
: Wednesday, November 01, 2006 10:58 AM To: Imail_Forum@list.ipswitch.com Subject: RE: [IMail Forum] Update for SMTP vulnerability in 8.22 Oops, never mind. I misread the previous message. You were offering these as examples and advising to choose ONE, not use them all. ;-) That makes sense. *self

Re: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-11-01 Thread Doug Traylor
All a script kiddie needs to do is point their exploit script at your unprotected server's IP and it's toast. A gateway can't prevent that from happening. Not true in our case. A gateway does protect your server if it's the only way to get to said server. Our gateway AV works after the ASSP

Re: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-11-01 Thread Matt
I think that I was pretty clear about this in the sentence before the one that you quoted. Most people running IMail do not have the option of blocking access to SMTP (service providers for instance), and as long as one can get to the SMTP service and the SMTP service is not patched, it can

Re: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-11-01 Thread Len Conrad
I think that I was pretty clear about this in the sentence before the one that you quoted. with an front-end MX like IMGate taking raw Internet inbound, you can really shut down via firewall access to the SMTP service, almost completely hardending the SMTP service against attacks. 1. the

Re: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-11-01 Thread Matt
Len, et. al, IMail 8.x does not support Auth-only on any port, so it is not possible to just simply work around the vulnerability in this way. I agree that forcing SMTP Auth on the server itself would be best, while leaving the MX related stuff to the gateway. Redirecting 25 to 587 on a

RE: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-30 Thread Servei Tècnic [ MICROTECH ]
2006 1:39 Para: Imail_Forum@list.ipswitch.com Asunto: Re: [IMail Forum] Update for SMTP vulnerability in 8.22 Look at your smtp logs for send error 10038. That will be preceded by something like date time SMTPD(your-message-number) [the imail IP] connect the-offending-server-ip port 3442 date

Re: [IMail Forum] Update for SMTP vulnerability in 8.22...

2006-10-29 Thread Don Brown
kg KG KG -Original Message- KG From: [EMAIL PROTECTED] KG [mailto:[EMAIL PROTECTED] On Behalf Of Don Brown KG Sent: Saturday, October 28, 2006 12:30 KG To: Imail_Forum@list.ipswitch.com KG Subject: Re: [IMail Forum] Update for SMTP vulnerability in 8.22... KG Kevin, KG We need a stable

RE: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-28 Thread Rick Hogue
Hosting 1-800-866-2983 From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Matrosity Hosting Sent: Friday, October 27, 2006 9:06 PM To: Imail_Forum@list.ipswitch.com Subject: RE: [IMail Forum] Update for SMTP vulnerability in 8.22 I did upgrade to 2006.1 which is why I'm

RE: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-28 Thread Markus Gufler
Matt, I think that it would be wise for Ipswitch to reevaluate their approach to vulnerability patches. ... As a result, Ipswitch has lost goodwill, whereas if they had provided the patch back then, they would have gained goodwill. In my opinion Ipswitch has choosen to definitively

[IMail Forum] Update for SMTP vulnerability in 8.22...

2006-10-28 Thread Kevin Gillis
To: Tripp Allen Cc: Imail_Forum@list.ipswitch.com Subject: Re: [IMail Forum] Update for SMTP vulnerability in 8.22 Thank you very much for this fix! Many of us were between a rock and a hard place over this vulnerability and not being able to upgrade for a variety of reasons. I don't know what changed

RE: [IMail Forum] Update for SMTP vulnerability in 8.22...

2006-10-28 Thread Matrosity Hosting
: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Kevin Gillis Sent: Saturday, October 28, 2006 7:19 AM To: Imail_Forum@list.ipswitch.com Subject: [IMail Forum] Update for SMTP vulnerability in 8.22... Hi Don and all, Appreciate all the feedback - it definitely helped to shape and expedite

RE: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-28 Thread Matrosity Hosting
: Saturday, October 28, 2006 2:09 AMTo: Imail_Forum@list.ipswitch.comSubject: RE: [IMail Forum] Update for SMTP vulnerability in 8.22 Bill, we ended up having to reinstall 8.22 with lots of help from tech support and it cost us lots of customers as it took Ipswitch a week to get everything back

Re: [IMail Forum] Update for SMTP vulnerability in 8.22...

2006-10-28 Thread Gil Gomes
-Original Message-From: "Kevin Gillis" Sent 10/28/2006 7:19:19 AMTo: Imail_Forum@list.ipswitch.comSubject: [IMail Forum] Update for SMTP vulnerability in 8.22..."There is lots of productive work being done on 2006.2 (addressing issuesraised here, in technical support and adding some new stuff) "

[IMail Forum] Update for SMTP vulnerability in 8.22 - Software Issue

2006-10-28 Thread Greg Shepherd
Originally, When I upgraded to 8.22. I had problems with ODBC File being the correct file. Before applying the SMTP Protocol DLL file, I attempted to apply 8.22 HF1 HF2. I was unable to install these hotfixes due to OBDC Files was not found or wrong version. Does anyone have a solution for

Re: [IMail Forum] Update for SMTP vulnerability in 8.22...

2006-10-28 Thread Don Brown
-Original Message- GG From: Kevin Gillis GG Sent 10/28/2006 7:19:19 AM GG To: Imail_Forum@list.ipswitch.com GG Subject: [IMail Forum] Update for SMTP vulnerability in 8.22... GG There is lots of productive work being done on 2006.2 (addressing issues GG raised here, in technical support

RE: [IMail Forum] Update for SMTP vulnerability in 8.22...

2006-10-28 Thread Kevin Gillis
Of Don Brown Sent: Saturday, October 28, 2006 12:30 To: Imail_Forum@list.ipswitch.com Subject: Re: [IMail Forum] Update for SMTP vulnerability in 8.22... Kevin, We need a stable release of 2006 with at least the same, working functionality of 8.22. We don't care a thing about new racing stripes

RE: [IMail Forum] Update for SMTP vulnerability in 8.22...

2006-10-28 Thread Grant Griffith
-Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Kevin Gillis Sent: Saturday, October 28, 2006 2:16 PM To: Imail_Forum@list.ipswitch.com Cc: Jason Benton (Jason Benton) Subject: RE: [IMail Forum] Update for SMTP vulnerability in 8.22... Hi Don, Good points

RE: [IMail Forum] Update for SMTP vulnerability in 8.22...

2006-10-28 Thread Kevin Gillis
-Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Grant Griffith Sent: Saturday, October 28, 2006 22:45 To: Imail_Forum@list.ipswitch.com Subject: RE: [IMail Forum] Update for SMTP vulnerability in 8.22... Kevin, I used to be notified about these every 30

RE: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread Servei Tècnic [ MICROTECH ]
Tripp Allen Enviado el: viernes, 27 de octubre de 2006 3:57 Para: Imail_Forum@list.ipswitch.com Asunto: [IMail Forum] Update for SMTP vulnerability in 8.22 The steps and files to update 8.22 are located here: http://support.ipswitch.com/kb/IM-20061026-JH01.htm Note this will ONLY work for 8.22

RE: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread John T \(Lists\)
] On Behalf Of Servei Tècnic [ MICROTECH ] Sent: Friday, October 27, 2006 12:37 AM To: Imail_Forum@list.ipswitch.com Subject: RE: [IMail Forum] Update for SMTP vulnerability in 8.22 Is Ipswitch planning to check/fix prior 8.22 versions? Any SMTP update for 8.15 will work in 8.05?? If i

AW: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread Martin Schaible
.:. Paessler GmbH.:. SmarterTools Von: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Im Auftrag von Tripp AllenGesendet: Freitag, 27. Oktober 2006 03:57An: Imail_Forum@list.ipswitch.comBetreff: [IMail Forum] Update for SMTP vulnerability in 8.22 The steps

RE: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread marc
in 8.22, so is same in 8.05 and 8.15 Thxs, Pere Ginabreda -Mensaje original- De: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] nombre de Tripp Allen Enviado el: viernes, 27 de octubre de 2006 3:57 Para: Imail_Forum@list.ipswitch.com Asunto: [IMail Forum] Update for SMTP vulnerability in 8.22

Re: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread Mike N
Thanks for the update - this was squeezing some people too tightly to make the jump from 8.22 to 2006.1 in time. - Original Message - From: Tripp Allen Sent: Thursday, October 26, 2006 9:56 PM Subject: [IMail Forum] Update for SMTP vulnerability in 8.22 The steps and files to update

Re: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread Robbie Pardue
I talked to Kevin Gillis. The short answer is no patch for anything older than 8.22.- Original Message From: marc [EMAIL PROTECTED]To: Imail_Forum@list.ipswitch.comSent: Friday, October 27, 2006 4:51:00 AMSubject: RE: [IMail Forum] Update for SMTP vulnerability in 8.22any news about

Re: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread marc
in 8.22, so is same in 8.05 and 8.15 Thxs, Pere Ginabreda -Mensaje original- De: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] nombre de Tripp Allen Enviado el: viernes, 27 de octubre de 2006 3:57 Para: Imail_Forum@list.ipswitch.com Asunto: [IMail Forum] Update for SMTP vulnerability in 8.22

RE: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread Beach Computers
@list.ipswitch.comSubject: Re: [IMail Forum] Update for SMTP vulnerability in 8.22 I talked to Kevin Gillis. The short answer is no patch for anything older than 8.22. - Original Message From: marc [EMAIL PROTECTED]To: Imail_Forum@list.ipswitch.comSent: Friday, October 27, 2006 4:51:00

Re: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread Dave Doherty
Or run everything through a gateway. That what I'm going to do. -d - Original Message - From: Beach Computers To: Imail_Forum@list.ipswitch.com Sent: Friday, October 27, 2006 10:44 AM Subject: RE: [IMail Forum] Update for SMTP vulnerability in 8.22 So

RE: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread marc
:[EMAIL PROTECTED] On Behalf Of Robbie Pardue Sent: Friday, October 27, 2006 9:24 AM To: Imail_Forum@list.ipswitch.com Subject: Re: [IMail Forum] Update for SMTP vulnerability in 8.22 I talked to Kevin Gillis. The short answer is no patch for anything older than 8.22. - Original Message

RE: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread David Waller
To: Imail_Forum@list.ipswitch.com Subject: Re: [IMail Forum] Update for SMTP vulnerability in 8.22 Thx for this update, and wow, how a software can be useless after only 1,5 years!? This negligently attitude is not more acceptable. I will not pay 1000 USD and have next year after SA expired again a security

RE: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread Servei Tecnic [ MICROTECH ]
just get hacked... -Mensaje original-De: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]En nombre de Beach ComputersEnviado el: viernes, 27 de octubre de 2006 16:45Para: Imail_Forum@list.ipswitch.comAsunto: RE: [IMail Forum] Update for SMTP vulnerability in 8.22 So

Re: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread Brian T.
How can you tell? Brian T. - Original Message - From: Servei Tecnic [ MICROTECH ] To: Imail_Forum@list.ipswitch.com Sent: Friday, October 27, 2006 11:01 AM Subject: RE: [IMail Forum] Update for SMTP vulnerability in 8.22 just get hacked

RE: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread Welch, Tom
Right. Because that is a quicker fix than upgrading to 8.22 -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of marc Sent: Friday, October 27, 2006 9:55 AM To: Imail_Forum@list.ipswitch.com Subject: RE: [IMail Forum] Update for SMTP vulnerability in 8.22

RE: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread marc
to bring out a fix for previous veriosn by all means, I think they should but don't expect them to do so. David -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of marc Sent: 27 October 2006 15:28 To: Imail_Forum@list.ipswitch.com Subject: Re: [IMail Forum] Update

RE: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread Servei Tècnic [ MICROTECH ]
Forum] Update for SMTP vulnerability in 8.22 How can you tell? Brian T. - Original Message - From: Servei Tecnic [ MICROTECH ] To: Imail_Forum@list.ipswitch.com Sent: Friday, October 27, 2006 11:01 AM Subject: RE: [IMail Forum

RE: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread mnapuran
So am I to understand that ASSP somehow prevents the vulnerabtility from being a problem? Mike N FXOL To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ:

Re: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread Robbie Pardue
You can install 8.22 (and patch it) and select "Activate Later" when you launch "the smiley man". Nothing (according to techsupport) is restricted...except that you have to have activated it within 30 days or it will shut down.-Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL

RE: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread Chris Moody
PROTECTED] [mailto:[EMAIL PROTECTED] Behalf Of [EMAIL PROTECTED] Sent: Friday, October 27, 2006 12:28 PM To: Imail_Forum@list.ipswitch.com Subject: RE: [IMail Forum] Update for SMTP vulnerability in 8.22 So am I to understand that ASSP somehow prevents the vulnerabtility from being a problem? Mike N

Re: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread Chris McFarling
How can one verify that this patch is actually installed? I downloaded IMail822.exe from the link Tripp posted and installed it. I was never prompted for any activation info during the install. I don't see any recent dates on the SMTP related files either SMTPd32.exe - 11/30/2005 3:18PM

Re: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread Bill Green dfn Systems
Thank you, Robbie, and Michael. That's what was making me uneasy. I had a vague memory of some concerns over activation when 8.2 was new. I've downloaded 8.22 from the link in the KB article Tripp posted. It is named imail8.22.exe and is 23,639KB. The KB labels it an update, but I believe

RE: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread Neil Olson
Forum] Update for SMTP vulnerability in 8.22 How can one verify that this patch is actually installed? I downloaded IMail822.exe from the link Tripp posted and installed it. I was never prompted for any activation info during the install. I don't see any recent dates on the SMTP related files

RE: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread Cert
PROTECTED] [mailto:[EMAIL PROTECTED] Behalf Of [EMAIL PROTECTED] Sent: Friday, October 27, 2006 12:28 PM To: Imail_Forum@list.ipswitch.com Subject: RE: [IMail Forum] Update for SMTP vulnerability in 8.22 So am I to understand that ASSP somehow prevents the vulnerabtility from being a problem

Re: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread kztechinfo - cribellum
Sent: Friday, October 27, 2006 12:57 PM Subject: Re: [IMail Forum] Update for SMTP vulnerability in 8.22 How can one verify that this patch is actually installed? I downloaded IMail822.exe from the link Tripp posted and installed it. I was never prompted for any activation info during the install

RE: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread Tripp Allen
@list.ipswitch.com Subject: Re: [IMail Forum] Update for SMTP vulnerability in 8.22 How can one verify that this patch is actually installed? I downloaded IMail822.exe from the link Tripp posted and installed it. I was never prompted for any activation info during the install. I don't see any recent dates

Re: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread Robbie Pardue
Green dfn Systems [EMAIL PROTECTED]To: Imail_Forum@list.ipswitch.comSent: Friday, October 27, 2006 10:05:20 AMSubject: Re: [IMail Forum] Update for SMTP vulnerability in 8.22 Thank you, Robbie, and Michael. That's what was making me uneasy. I had a vague memory of some concerns over activatio

Re: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread Mike Leonard
Running IMail822.exe only gets you upgraded to the version that *can* be patched. You still need to download SMTPProtocol.zip and replace the .dll. Mike Chris McFarling wrote: How can one verify that this patch is actually installed? I downloaded IMail822.exe from the link Tripp posted and

RE: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread Tripp Allen
, 2006 1:07 PM To: Imail_Forum@list.ipswitch.com Subject: RE: [IMail Forum] Update for SMTP vulnerability in 8.22 Hello! I am no email expert, and I didn't feel comfortable setting up a full blown gateway (ASSP, IMGATE, etc...) while waiting for the 8.22 patch, so my kludge was to just block all

RE: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread Beach Computers
, interception or interference. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Tripp Allen Sent: Friday, October 27, 2006 1:17 PM To: Imail_Forum@list.ipswitch.com Subject: RE: [IMail Forum] Update for SMTP vulnerability in 8.22 The patch is here: http

RE: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread Grant Griffith
PROTECTED] On Behalf Of Chris Moody Sent: Friday, October 27, 2006 12:31 PM To: Imail_Forum@list.ipswitch.com Subject: RE: [IMail Forum] Update for SMTP vulnerability in 8.22 ASSP, IMGATE, , Barracuda and Alligate all sit in front of the mail server and act as a gateway. If you keep your mail server

Re: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread Imail
To: Imail_Forum@list.ipswitch.com Subject: RE: [IMail Forum] Update for SMTP vulnerability in 8.22 The patch is here: http://support.ipswitch.com/kb/IM-20061026-JH01.htm You need to download the updated smtpprotocol file and follow the instructions to replace it. Tripp -Original Message- From: [EMAIL

Re: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread Imail
Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Cert Sent: Friday, October 27, 2006 1:07 PM To: Imail_Forum@list.ipswitch.com Subject: RE: [IMail Forum] Update for SMTP vulnerability in 8.22 Hello! I am no email expert, and I didn't feel comfortable setting up a full blown

Re: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread Evan Eggers
FWIW I have been shocked NOT to have seen any evidence described of scanning for this vulnerablity here, and I wonder if it's because we changed our default Hello Message in advanced SMTP configuration such that it no longer mention imail. The default Imail response to the initial hello

RE: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread Beach Computers
Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Grant Griffith Sent: Friday, October 27, 2006 1:42 PM To: Imail_Forum@list.ipswitch.com Subject: RE: [IMail Forum] Update for SMTP vulnerability in 8.22 This is not true! We have an IMGate solution and were hit this morning

RE: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread Rick Klinge
Anyone know of a possible way to close this off in visnetic by a filter? I think Greg Linares [EMAIL PROTECTED] discovered/wrote the exploit, on or about the 19th, so you might check with him. ~Rick _ Virus Scanned and

Re: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread Bill Green dfn Systems
To: Imail_Forum@list.ipswitch.com Sent: Friday, October 27, 2006 11:14 AM Subject: Re: [IMail Forum] Update for SMTP vulnerability in 8.22 Yes, confirmed. Stop your services, run the imail8.22, launch the "smiley man", activate or trial, stop the smt

Re: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread Dave Doherty
Does the current 8.22download include the December 2005 patch?

Re: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread Dave Doherty
2006 4:52 PM Subject: Re: [IMail Forum] Update for SMTP vulnerability in 8.22 Does the current 8.22download include the December 2005 patch?

RE: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread Matrosity Hosting
] [mailto:[EMAIL PROTECTED] On Behalf Of Dave DohertySent: Friday, October 27, 2006 5:05 PMTo: Imail_Forum@list.ipswitch.comSubject: Re: [IMail Forum] Update for SMTP vulnerability in 8.22 Maybe I just answered my own question. The December 2005 "patch" is 23MB, so that's probably t

RE: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread John T \(Lists\)
Thx for this update, and wow, how a software can be useless after only 1,5 years!? This negligently attitude is not more acceptable. I will not pay 1000 USD and have next year after SA expired again a security problem. Is this a new manner to force to upgrade? I believe Imail 8.15 is over 2

Re: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread Dave Doherty
My copy was compiled in Feb 05, so one year and eight months. - Original Message - From: John T (Lists) [EMAIL PROTECTED] To: Imail_Forum@list.ipswitch.com Sent: Friday, October 27, 2006 5:30 PM Subject: RE: [IMail Forum] Update for SMTP vulnerability in 8.22 Thx for this update

RE: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread John T \(Lists\)
Right, but also partially responsible by Ipswitch. Its the first time in 10 years that a software seems to be useless after 3 years only, when IMail 8.x was coming out... again, this not acceptable. QuickBooks 2003 is no longer usable if you want to do a common list of things. QuickBooks prior

Re: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread Doug Traylor
So am I to understand that ASSP somehow prevents the vulnerabtility from being a problem? With the recent report of the exploit getting through IMGate, this is still a good question. Is there anybody using ASSP directly in front of IMail, that has suffered from this exploit? Will the

Re: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread Brian T.
Anybody willing to give any input as to what to look for? Brian - Original Message - From: Brian T. To: Imail_Forum@list.ipswitch.com Sent: Friday, October 27, 2006 11:23 AM Subject: Re: [IMail Forum] Update for SMTP vulnerability in 8.22 How can you

RE: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread marc
does your desktop software examples have any security holes to compromise a server shared with hundreds of customers? make a serious comparison to convince me, that this is common. we are talking about business server software not for 100 bugs. marc QuickBooks 2003 is no longer usable if you

Re: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread Robbie Pardue
ge From: Brian T. [EMAIL PROTECTED]To: Imail_Forum@list.ipswitch.comSent: Friday, October 27, 2006 4:18:27 PMSubject: Re: [IMail Forum] Update for SMTP vulnerability in 8.22 Anybody willing to give any input as to what to look for? Brian - Original Message - From: Brian T

Re: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread Matt
Doug, The only way to get complete protection from the exploit it to make sure that IMail doesn't answer the Internet with SMTP. If you have IMail 8.x or earlier, and you have customers connecting to IMail for SMTP, you cannot sufficiently lock it down unless your firewall has some form of

AW: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread Martin Schaible
850.656.2644 From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Dave DohertySent: Friday, October 27, 2006 5:05 PMTo: Imail_Forum@list.ipswitch.comSubject: Re: [IMail Forum] Update for SMTP vulnerability in 8.22 Maybe I just answered my own question. The December 2005 "patch" i

RE: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread John T \(Lists\)
does your desktop software examples have any security holes to compromise a server shared with hundreds of customers? make a serious comparison to convince me, that this is common. we are talking about business server software not for 100 bugs. marc Neither I nor any one else would consider

RE: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread Matrosity Hosting
: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Martin SchaibleSent: Friday, October 27, 2006 8:43 PMTo: Imail_Forum@list.ipswitch.comSubject: AW: [IMail Forum] Update for SMTP vulnerability in 8.22 Hi, Bill, i do not agree with your latest statement. As everybody knows, Ipswitch spent

RE: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread Grant Griffith
] [mailto:[EMAIL PROTECTED] On Behalf Of Brian T. Sent: Friday, October 27, 2006 7:18 PM To: Imail_Forum@list.ipswitch.com Subject: Re: [IMail Forum] Update for SMTP vulnerability in 8.22 Anybody willing to give any input as to what to look for? Brian - Original Message

RE: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-27 Thread marc
I do not have any reason to change the meaning of my post. Just read the subject to this theard and than you will understand the meaning of useless. marc At 02:46 28.10.2006, you wrote: does your desktop software examples have any security holes to compromise a server shared with hundreds of

[IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-26 Thread Tripp Allen
The steps and files to update 8.22 are located here: http://support.ipswitch.com/kb/IM-20061026-JH01.htm Note this will ONLY work for 8.22. Thanks, Tripp Allen Software Development Manager, Messaging Ipswitch, Inc.

RE: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-26 Thread John Doyle
] Update for SMTP vulnerability in 8.22 The steps and files to update 8.22 are located here: http://support.ipswitch.com/kb/IM-20061026-JH01.htm Note this will ONLY work for 8.22. Thanks, Tripp Allen Software Development Manager, Messaging Ipswitch, Inc.

RE: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-26 Thread Michael Thomas - Mathbox
Tripp, I wanted to say Thank You to you and Ipswitch. I hold an SA that entitles me to upgrade to 2006, but I still preferred to run 8.22 for a while longer. Downloaded and installed the patch. Now I can go worry about something else. Michael ThomasMathbox978-683-67181-877-MATHBOX (Toll

RE: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-26 Thread Douglas Brantley
The install was very smooth and easy. Many thanks to Tripp and to Ipswitch. db To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

RE: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-26 Thread Rick Hogue
Thank you Tripp for getting this done in your department. Rick Hogue Intent.net From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Tripp Allen Sent: Thursday, October 26, 2006 9:57 PM To: Imail_Forum@list.ipswitch.com Subject: [IMail Forum] Update for SMTP

Re: [IMail Forum] Update for SMTP vulnerability in 8.22

2006-10-26 Thread Don Brown
Thank you very much for this fix! Many of us were between a rock and a hard place over this vulnerability and not being able to upgrade for a variety of reasons. I don't know what changed your mind about continuing to support 8.22, but whatever it was surely raised your net worth with us. I'll