Crashing Internet Anywhere Mail Server
Reported Feburary 10, 2000 by Nubuo Miwa
Two problems were discovered in the mail server that can lead to denial of service attacks against the system.
Attack 1: by sending a specific string of characters as the parameter of the RETR command the server can be made to crash.
Attack 2: by opening 3000 or more connections on the SMTP port the server will respond with an error reporting to many connects. By sending a second large set of connections (800 or more) immediately thereafter the service will crash.