Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

SMTP:COMMAND:WIZ

Severity

Critical

Recommended

No

Recommended Action

Drop

Category

SMTP

Release Date

2003/04/22

Update Number

1213

Supported Platforms

di-5.3+, idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

SMTP: "wiz" Command


This signature detects attempts to exploit a known vulnerability against the SMTP server support for the WIZ command. An attacker can attempt to determine if the SMTP server under attack supports the WIZ command. Support for this command can provide anonymous root access for the attacker. The command must be enabled for a successful attack.

Extended Description

Sendmail is the standard Mail Transfer Agent for Unix systems. Older versions of Sendmail have the WIZ command enabled. The WIZ command was originally intended to allow administrators to access a remote shell on the host. If the command is enabled then a remote attacker can use it to gain root access on the vulnerable host.

Affected Products

  • Sendmail Consortium Sendmail 4.1.0
  • Sendmail Consortium Sendmail 4.55.0
  • Sendmail Consortium Sendmail 5.59.0

References

  • BugTraq: 2897
  • CERT: CA-1993-14
  • CVE: CVE-1999-0145

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out