Vulnerability Scanning Solutions, LLC.
Our Process
What We Scan For
Sample Report
Client List
Contact Us
What We Scan For
Family: Gain a shell remotely --> Category: destructive_attack

NAI Management Agent overflow Vulnerability Scan

Vulnerability Scan Summary
Acertains if the remote NAI WebShield SMTP Management trusts us

Detailed Explanation for this Vulnerability Test

The remote NAI WebShield SMTP Management tool
is vulnerable to a buffer overflow which allows
a possible hacker to gain execute arbitrary code
on this host when it is issued a too long argument
as a configuration parameter.

In addition to this, it allows a possible hacker to disable
the service at will.

* To re-enable the service :

- execute regedit
- edit the registry key 'Quarantine_Path' under
HKLM\SOFTWARE\Network Associates\TVD\WebShield SMTP\MailScan
- change its value from 'XXX...XXX' to the valid path to
the quarantine folder.
- restart the service

Solution : filter incoming traffic to this port. You
may also restrict the set of trusted hosts in the
configuration console :
- go to the 'server' section
- select the 'trusted clients' tab
- and set the data accordingly

Threat Level: High

Click HERE for more information and discussions on this network vulnerability scan.


P.O. Box 827051

Pembroke Pines, FL 33082-7051

Vulnerability Scanning Solutions, LLC.