Vulnerabilities of Kolab 3.4

Homer Dokes <[email protected]>
Newsgroups gmane.comp.kde.devel.kroupware
Message-ID <960f4cd5-2584-7eb5-3590-747b2aa165a4__29767.0448360563$1556211244$gmane$org@mail.inct.net>
Greetings all,

Recently we have been experiencing a tremendous number of spam/malware 
emails with origination addresses from our own Kolab server members.  
Our Kolab server sits behind a firewall allowing only ports 587, 25, 
8585 (for the gui interface) and 993 for through traffic.

What kind of vulnerabilities, if any, exist for a would be attacker to 
extract email information from the server under these conditions.  In a 
few instances we have actually had 'threaded' email exchanges shown in 
the body of the malware email making it look legit.  What is accessible 
on the Kolab server that would allow anyone to retrieve that information 
through those ports? Our concern is that the damage is already done and 
we are compromised.

Thank you,

hdokes
_______________________________________________
users mailing list
[email protected]
https://lists.kolab.org/mailman/listinfo/users
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.