Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 4 of 4
  1. #1
    Member
    Join Date
    Aug 2010
    Posts
    11

    Question Mail Server Fails PCI Compliance because of SMTP Buffer Overflow Threat

    Hey all I get this message when failing the PCI compliance:
    The remote SMTP server is vulnerable to a buffer overflow. Description : The remote SMTP server crashes when it is sent a command with a too long argument. An attacker might use this flaw to kill this service or worse, execute arbitrary code on your server.

    I have enabled the SMTP tweak and it still fails. Is there a way I can allow the PCI compliance scanner to bypass the SMTP proxy or make it so the scanner gets a message with cPanel/WHM?

  2. #2
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Sep 2007
    Posts
    139

    Default

    Generally, I have seen this error caused by some kind of firewall. The pci scanner makes multiple requests in a short period of time and the scanner gets blocked. It shows that it can't connect after sending a large string and assumes that it crashed and that is why it is not responding. You can just whitelist the scanner's ip or try just providing the logs showing that exim did not crash.

  3. #3
    Member
    Join Date
    Aug 2010
    Posts
    11

    Default

    I tried to white list it and it still fails. It must be something with cPanel as we have white listed the IP, done REJECT instead of DROP on IPTABLES. We are still looking.

  4. #4
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Sep 2007
    Posts
    139

    Default

    What iptables do you have set for port 25?

Similar Threads & Tags
Similar threads

  1. Security Metrics PCI compliance - Exim fails test.
    By jols in forum E-mail Discussions
    Replies: 6
    Last Post: 12-11-2008, 11:55 PM
  2. Replies: 5
    Last Post: 08-15-2006, 06:28 PM
  3. Buffer Overflow Attemp?
    By fizz in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 04-07-2004, 10:54 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube