_____ _ _ _____ _____ _____ _____ / ___| |_| | _ \| _ | _ |_ _| | (___| _ | [_)_/| (_) | (_) | | | \_____|_| |_|_| |_||_____|_____| |_| C. H. R. O. O. T. SECURITY GROUP - -- ----- --- -- -- ---- --- -- - http://www.chroot.org _ _ _ _____ ____ ____ __ _ Hacks In Taiwan | |_| | |_ _| __| | \| | Conference 2008 | _ | | | | | (__| () | | |_| |_|_| |_| \____|____|_|\__| http://www.hitcon.org Title =========:: Nopam+ Authentication Bypass Vulnerability Author ========:: Roamer IRC ===========:: irc.chroot.org #chroot ScriptName ====:: Green-Computing Nopam+ Spam Filter ScriptVendor ==:: http://www.green-computing.com/ooweb/index/index.php ______________________ [Authentication Vulnerability] The school I attended had installed Nopam+ to filter spam. Now I receive the nopam+ report everyday. But I found something suspicious. So I surveyed the link as below: http://nopam.xxx.edu.tw/cgi-bin/mailgw/openwebmail.pl?folder=spam-mail&action=listmessages&logindomain=(mail.xxx.edu.tw)&loginname=(xxxxxxxx)&password=(xxxxxxx) I found that I can modify the loginname and use the same password(not my e-mail password) to login all spam-mail box. Even I can modify the logindomain to transfer to another servers' accounts. If I am an attacker, I can fileter and find some useful messages in all the spam-mail box. ______ [NOTE] !! This is just for educational purposes, DO NOT use for illegal. !!