Short Name |
SMTP:COMMAND:WIZ |
---|---|
Severity |
Critical |
Recommended |
No |
Recommended Action |
Drop |
Category |
SMTP |
Release Date |
2003/04/22 |
Update Number |
1213 |
Supported Platforms |
di-5.3+, idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to exploit a known vulnerability against the SMTP server support for the WIZ command. An attacker can attempt to determine if the SMTP server under attack supports the WIZ command. Support for this command can provide anonymous root access for the attacker. The command must be enabled for a successful attack.
Sendmail is the standard Mail Transfer Agent for Unix systems. Older versions of Sendmail have the WIZ command enabled. The WIZ command was originally intended to allow administrators to access a remote shell on the host. If the command is enabled then a remote attacker can use it to gain root access on the vulnerable host.