Re: [twsocket] Buffer overflow in SMTP

2007-03-16 Thread Piotr Dałek
David Colliver napisał(a): > I just happened to come across the vulnerability as someone has reported it > on many security websites. They have described it as this and have test > code, but the code they use to test is not something I understand. I know of > vulnerabilities, but as I am more a

Re: [twsocket] Buffer overflow in SMTP

2007-03-16 Thread David Colliver
Hi, I will look for these, but when I wrote the mailserver, I was confident at programming but little experience of Delphi or ICS, so I don't think I will actually have written code like that. However, I definately have a look. Thanks for your help. Arno, Yes, only SMTP and POP clients are wit

Re: [twsocket] Buffer overflow in SMTP

2007-03-16 Thread Francois PIETTE
> Try this > http://secunia.com/advisories/22559/ > This one has more information, including code to exploit it. > http://www.securityfocus.com/bid/20709 Both are not a vulnerabilities in ICS but in an application using ICS. The vulnerability is in the way the application handle data received fro

Re: [twsocket] Buffer overflow in SMTP

2007-03-16 Thread Piotr Dałek
David Colliver napisał(a): > Try this > http://secunia.com/advisories/22559/ > > There are two mentions of it. This one for SMTP, the other for the POP3. > > The software I developed was a mailserver. Now that's a whole different thing! I don't remember that ICS has/had any SMTP/POP3 _server_

Re: [twsocket] Buffer overflow in SMTP

2007-03-16 Thread Arno Garrels
David Colliver wrote: > Try this > http://secunia.com/advisories/22559/ > > There are two mentions of it. This one for SMTP, the other for the > POP3. Only, there's neither a SMTP nor a POP3 server shipped with ICS. You propably need to rework your code. -- Arno Garrels [TeamICS] http://www.over

Re: [twsocket] Buffer overflow in SMTP

2007-03-16 Thread David Colliver
Try this http://secunia.com/advisories/22559/ There are two mentions of it. This one for SMTP, the other for the POP3. The software I developed was a mailserver. It has client components and server components to handle both sides... One to receive SMTP, the other to send SMTP, one to receive PO

Re: [twsocket] Buffer overflow in SMTP

2007-03-16 Thread Arno Garrels
David Colliver wrote: > Hi Piotr, > > I just happened to come across the vulnerability as someone has > reported it on many security websites. Any links? BTW: You talked about client components ( SMTP or POP3 ? ), targets of buffer overflow-attacks usually are servers, otherwise the server wa

Re: [twsocket] Buffer overflow in SMTP

2007-03-16 Thread David Colliver
Hi Piotr, I just happened to come across the vulnerability as someone has reported it on many security websites. They have described it as this and have test code, but the code they use to test is not something I understand. I know of vulnerabilities, but as I am more a web developer than a win

Re: [twsocket] Buffer overflow in SMTP

2007-03-16 Thread Piotr Dałek
David Colliver napisał(a): > Hi, > > I am using a fairly old version of ICS from 2002, with Delphi 5. I have not > done much programming in Delphi since then, but I have become aware of a > buffer overflow in the SMTP part of my application. At this moment, I don't > know if it is ICS or my app

Re: [twsocket] Buffer overflow in SMTP

2007-03-16 Thread Francois PIETTE
> Also, if I download the latest ICS, will there be anything that is likely > to cause me programming difficulties? The latest ICS-V5 should probably work immediately with your old Delphi 5. If not, only minor issue could pops up. Feel free to report any problem here. Don't forget to include the

[twsocket] Buffer overflow in SMTP

2007-03-16 Thread David Colliver
Hi, I am using a fairly old version of ICS from 2002, with Delphi 5. I have not done much programming in Delphi since then, but I have become aware of a buffer overflow in the SMTP part of my application. At this moment, I don't know if it is ICS or my app that is causing it. In the USER or RC