Enabling the Spammers
Spammers are having a field day with a string of recently discovered security vulnerabilities in MailEnable, an e-mail server program offered by many large, dedicated Web hosting companies.
Over the past few months, MailEnable has released updates at least a half dozen times to fix quite serious vulnerabilities in its various products that attackers can use to completely hijack vulnerable systems. Unfortunately, it looks like many customers either are not registered (and thus not receiving e-mail notices from MailEnable about the flaws), or they are simply ignoring the alerts.
"We are seeing hundreds of mail servers getting compromised via the rash of MailEnable vulnerabilities that have been discovered and announced in the last few months," said Lawrence Baldwin, chief forensics officer for myNetWatchman.