firewall BarracudaSpam Filter Beset by Major Flaw
Explore the latest news and trends  

Keep yourself up to date with one of the following options:

  • Explore more news around Spam/Phishing, Malware/Cyber-attacks and Antivirus
  • Receive news and special offers from SPAMfighter directly in your inbox.
  • Get free tips and tricks from our blog and improve your security when surfing the net.

BarracudaSpam Filter Beset by Major Flaw

A lack of input sanitization in the Linux-based Barracuda spam firewall Web interface, combined with privilege elevation techniques, can allow a full system compromise by unauthenticated users.

"This is a major vulnerability: exposed and unpatched systems can be fully and simply accessed by any attacker," Matthew Hall, a security engineer for the Internet Defence Incident Response Team at UK-based ECSC Ltd. "As a key security device, this represents a highly significant problem."

Hall says his team has been responding to the incident on behalf of a client who uses Barracuda. "We are now aware the latest firmware version provides some degree of protection," says Hall.

According to the advisory, using this vulnerability, it is possible to leverage further privileges, as the http daemon is granted root level access to several system commands. Access to some commands allowed further privilege escalation by setting the 'suid' bit on several othe...

ยป Application Development Trade - Shawna McAlearney - 07-08-2006

3 simple steps to update drivers on your Windows PCSlow PC? Optimize your Slow PC with SLOW-PCfighter!Email Cluttered with Spam? Free Spam Filter!

Exchange Anti Spam Filter
Go back to previous page