Tag
Detection of Potential Command and Control via SMTP on Port 26/TCP
1 rule 3 TTPsAdversaries, including the BadPatch malware family, utilize non-standard port 26/TCP for SMTP-based command and control and data exfiltration to evade traditional security monitoring.
Tabs Mail Carrier 2.5.1 MAIL FROM Buffer Overflow Vulnerability
2 rules 1 TTPTabs Mail Carrier 2.5.1 is vulnerable to a buffer overflow in the MAIL FROM SMTP command, allowing remote attackers to execute arbitrary code by sending a crafted MAIL FROM parameter with an oversized buffer to overwrite the EIP register and execute a bind shell payload via port 25.
Maddy Mail Server LDAP Filter Injection Vulnerability
2 rules 3 TTPsMaddy Mail Server is vulnerable to LDAP injection via unsanitized username in the `auth.ldap` module, enabling identity spoofing, LDAP directory enumeration, and attribute value extraction by injecting arbitrary LDAP filter expressions through the username field in SMTP submission or IMAP LOGIN interfaces.