| |
WebAdmin is a remote administration utility which allows administrators to manage Alt-N's MDaemon, RelayFax and WorldClient products. Recently this has become a standard module for the company's MDaemon mail server, altough it remains available independently as well.
It is possible for a domain administrator within the default domain of a
MDaemon server to gain access to the server's "MDaemon" account through the WebAdmin. This is the account which processes remote server and mailinglist commands, which are authenticated by putting a user's email address and password in the subject field of a message.
By taking over this account and enabling mail access to it a malicious
domain administrator could gain access to the system queue, the contents of which are by default only stored on disk and not accessible.
It is important to note that this queue processes the messages for all
domains on the server, not just the local one.
|
|
|
|
|