
<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Sec-1 Labs</title>
	<atom:link href="http://www.sec-1.com/blog/?feed=rss2" rel="self" type="application/rss+xml" />
	<link>http://www.sec-1.com/blog</link>
	<description>Tools, Advisories, Whitepapers</description>
	<lastBuildDate>Fri, 24 Feb 2012 14:45:26 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Advisory: Multiple WatchGuard Log and Report Manager Vulnerabilities</title>
		<link>http://www.sec-1.com/blog/?p=252</link>
		<comments>http://www.sec-1.com/blog/?p=252#comments</comments>
		<pubDate>Thu, 22 Dec 2011 12:28:49 +0000</pubDate>
		<dc:creator>waynem</dc:creator>
				<category><![CDATA[Advisories]]></category>

		<guid isPermaLink="false">http://www.sec-1.com/blog/?p=252</guid>
		<description><![CDATA[Sec-1 Security Advisory Advisory Name : WatchGuard Log and Report Manager: Persistent Cross-Site-Scripting (XSS) Vulnerability Release Date : 16/12/2011 Application : WSM 11.5.1 Log and Report Manager Platform : Windows Severity : HIGH. Persistent XSS Author : Wayne Murphy Vendor &#8230; <a href="http://www.sec-1.com/blog/?p=252">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<table style="border-collapse: separate; border-spacing: 0px;" width="640">
<tbody>
<tr valign="center">
<td style="border: none;"><center>Sec-1 Security Advisory</center></td>
</tr>
<tr>
<td style="border: none;">
<table style="border: none; border-collapse: separate; border-spacing: 0px;">
<tbody>
<tr>
<td style="border: none;" valign="center" width="40%"><strong>Advisory Name</strong></td>
<td style="border: none;" align="center" valign="center" width="3%">:</td>
<td style="border: none; font-size: small;" valign="center" width="57%">WatchGuard Log and Report Manager: Persistent Cross-Site-Scripting (XSS) Vulnerability</td>
</tr>
<tr>
<td style="border: none;" valign="center" width="40%"><strong>Release Date</strong></td>
<td style="border: none;" align="center" valign="center" width="3%">:</td>
<td style="border: none; font-size: small;" valign="center" width="57%">16/12/2011</td>
</tr>
<tr>
<td style="border: none;" valign="center" width="40%"><strong>Application</strong></td>
<td style="border: none;" align="center" valign="center" width="3%">:</td>
<td style="border: none; font-size: small;" valign="center" width="57%">WSM 11.5.1 Log and Report Manager</td>
</tr>
<tr>
<td style="border: none;" valign="center" width="40%"><strong>Platform</strong></td>
<td style="border: none;" align="center" valign="center" width="3%">:</td>
<td style="border: none;" valign="center" width="57%"><span style="font-size: small;">Windows</span></td>
</tr>
<tr>
<td style="border: none;" valign="center" width="40%"><strong>Severity</strong></td>
<td style="border: none;" align="center" valign="center" width="3%">:</td>
<td style="border: none; font-size: small;" valign="center" width="57%">HIGH. Persistent XSS</td>
</tr>
<tr>
<td style="border: none;" valign="center" width="40%"><strong>Author</strong></td>
<td style="border: none;" align="center" valign="center" width="3%">:</td>
<td style="border: none; font-size: small;" valign="center" width="57%">Wayne Murphy</td>
</tr>
<tr>
<td style="border: none;" valign="center" width="40%"><strong>Vendor Status</strong></td>
<td style="border: none;" align="center" valign="center" width="3%">:</td>
<td style="border: none; font-size: small;" valign="center" width="57%">Fixed in WSM 11.5.1 Update 1</td>
</tr>
<tr>
<td style="border: none;" valign="center" width="40%"><strong>Website</strong></td>
<td style="border: none;" align="center" valign="center" width="3%">:</td>
<td style="border: none; font-size: small;" valign="center" width="57%">http://www.sec-1.com/blog</td>
</tr>
</tbody>
</table>
</td>
</tr>
<tr valign="center">
<td style="border: none;"><span style="font-size: small;"><strong><span style="text-decoration: underline;">Vulnerability Summary:</strong></span></td>
</tr>
<tr>
<td style="border: none; font-size: small;">Cross site scripting vulnerabilities were discovered within the Log and Report Manager component of WatchGuard System Manager Version 11.5.1.
</td>
</tr>
<tr>
<td style="border: none; font-size: small;">Version 11.5.1 introduced the new Log and Report Manager (web interface) replacing the older LogViewer, Report Manager and Reporting Windows client components. The introduction of this web component introduced two types of cross site scripting vulnerabilities; Persistent and Reflected. With the persistent XSS vulnerability it is possible to send traffic containing malicious scripts to a WatchGuard XTM Firebox firewall that is sending logs to a WatchGuard LogServer. Upon viewing the logs within the new Log and Remote Manager Web UI, the malicious scripts then execute, potentially allowing attackers to gain elevated privileges in the users browser. The reflected XSS vulnerabilities allows an attacker to embed script code into maliciously formatted links. If the attacker enticed the user to follow the links, the embedded script code would then execute. The following line is taken from WatchGuard&#8217;s Release Notes for WSM 11.5.1 Update 1 &#8220;These vulnerabilities do not allow the attacker to gain access to your XTM appliance or change firewall rules, but could potentially allow the attacker to gain unauthorized access to your computer.&#8221;</td>
</tr>
<tr valign="center">
<td style="border: none; font-size: small;"><strong><span style="text-decoration: underline;">Exploit 1: Persistent XSS : FTP Method</span></strong></td>
</tr>
<tr>
<td style="border: none; font-size: small;">Script code embedded within the FTP username value is insecurely stored and retrieved from the database. Upon viewing the FTP Log within Log and Report Manager the embedded script code executes in the users browser.</p>
<p><strong>Example:</strong></p>
<p>Entering the username value: <em>&lt;script&gt;alert(&#8220;Username_XSS&#8221;)&lt;/script&gt;</em></p>
<p>Embeds the following escaped log entry within the Watchguard LogServer Database:</p>
<p><em>command=USER \x3cscript\x3ealert(\x22Username_XSS\x22)\x3c/script\\3e</em></p>
<p>When the malicious log entry is viewed the embedded script code executes within the browser.
</td>
</tr>
<tr valign="center">
<td style="border: none; font-size: small;"><strong><span style="text-decoration: underline;">Exploit 1: Persistent XSS : SMTP Method</span></strong></td>
</tr>
<tr>
<td style="border: none; font-size: small;">SMTP was also targeted during testing since this service is more commonly encountered during real world penetration testing. Furthermore, based on data collected from our firewall team, it is considered more likely that application aware proxies (with logging enabled) will be used for SMTP traffic.<br />
</tr>
<tr>
<td style="border: none; font-size: small;">The WatchGuard&#8217;s SMTP-Proxy logs all headers that are stripped from SMTP emails. By sending script code within a invalid SMTP header, data is <span style="line-height: 19px;">insecurely</span> stored and retrieved by the application allowing for Cross-Site-Scripting attacks.<br />
</tr>
<tr>
<td style="border: none; font-size: small;">For example, submitting the following SMTP header via the WatchGuard SMTP service will embed a JavaScript designed to display an alert box:</p>
<p><em>Bogus: \x3cscript\x3ealert(\x22XSS_Test_With_Encoding\x22)\x3c/script\x3e</em>
</td>
</tr>
<tr valign="center">
<td style="border: none; font-size: small;"><strong><span style="text-decoration: underline;">Exploit 2: Reflected XSS</span></strong></td>
</tr>
<tr>
<td style="border: none; font-size: small">The following two parameters were found to be be vulnerable to Reflected XSS attacks.</p>
<table style="border-collapse: separate; border-spacing: 0px;" width="400">
<tbody>
<tr>
<td><em>https://:4130/</em></td>
<td>- URL Parameter</td>
</tr>
<tr>
<td><em>https://:4130/auth/login</em></td>
<td>- from_page Parameter</td>
</tr>
</tbody>
</table>
</tr>
<tr>
<td style="border: none; font-size: small;">N.B. Modern browsers were unable to exploit the URL Parameter attack vector. An intercepting proxy had to be used to exploit this successfully.</td>
</tr>
<tr valign="center">
<td style="border: none; font-size: small;"><strong><span style="text-decoration: underline;">Vendor Response:</span></strong></td>
</tr>
<tr>
<td style="border: none; font-size: small;">The vendor has patched these issues in WSM Version 11.5.1 Update 1. A WatchGuard advisory has been released relating to these vulnerabilities; </p>
<p>http://watchguardsecuritycenter.com/2011/12/15/watchguard-releases-wsm-v11-5-1-update-1-xss-flaws-corrected/</td>
</tr>
<tr valign="center">
<td style="border: none; font-size: small;"><strong><span style="text-decoration: underline;">Common Vulnerabilities and Exposures (CVE) Information:</span></strong></td>
</tr>
<tr>
<td style="border: none; font-size: small;">The Common Vulnerabilities and Exposures (CVE) project has assigned the following names to these issues. These are candidates for inclusion in the CVE list (http://cve.mitre.org), which standardizes names for security problems.</td>
</tr>
<tr>
<td style="border: none;"></td>
</tr>
<tr valign="center">
<td style="border: none; font-size: small;"><strong>CVE : CVE-2011-4774</strong></td>
</tr>
<tr valign="center">
<td style="border: none;"></td>
</tr>
<tr align="center" valign="center">
<td style="border: none;"><center>Copyright 2011 Sec-1 LTD. All rights reserved.</center></td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.sec-1.com/blog/?feed=rss2&#038;p=252</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Advisory: Multiple Splunk Vulnerabilities</title>
		<link>http://www.sec-1.com/blog/?p=233</link>
		<comments>http://www.sec-1.com/blog/?p=233#comments</comments>
		<pubDate>Thu, 15 Dec 2011 09:21:59 +0000</pubDate>
		<dc:creator>Gary O'leary-Steele</dc:creator>
				<category><![CDATA[Advisories]]></category>

		<guid isPermaLink="false">http://www.sec-1.com/blog/?p=233</guid>
		<description><![CDATA[Sec-1 Security Advisory Advisory Name : Splunk Multiple Vulnerabilities Release Date : 14/12/2012 Application : Splunk 4.2.4, 4.2.3 and 4.2.2 tested Platform : Windows &#38; Linux Severity : Remote Compromise (root) Author : Gary O&#8217;Leary-Steele Vendor Status : Fixed in &#8230; <a href="http://www.sec-1.com/blog/?p=233">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<table style="border-collapse: separate; border-spacing: 0px;" width="640">
<tbody>
<tr valign="center">
<td><center>Sec-1 Security Advisory</center></td>
</tr>
<tr>
<td>
<table style="border-collapse: separate; border-spacing: 0px;">
<tbody>
<tr>
<td valign="center" width="40%"><strong>Advisory Name</strong></td>
<td align="center" valign="center" width="3%">:</td>
<td valign="center" width="57%"><span style="font-size: small;">Splunk Multiple Vulnerabilities </span></td>
</tr>
<tr>
<td valign="center" width="40%"><strong>Release Date</strong></td>
<td align="center" valign="center" width="3%">:</td>
<td valign="center" width="57%"><span style="font-size: small;">14/12/2012</span></td>
</tr>
<tr>
<td valign="center" width="40%"><strong>Application</strong></td>
<td align="center" valign="center" width="3%">:</td>
<td valign="center" width="57%"><span style="font-size: small;">Splunk 4.2.4, 4.2.3 and 4.2.2 tested</span></td>
</tr>
<tr>
<td valign="center" width="40%"><strong>Platform</strong></td>
<td align="center" valign="center" width="3%">:</td>
<td valign="center" width="57%"><span style="font-size: small;">Windows &amp; Linux</span></td>
</tr>
<tr>
<td valign="center" width="40%"><strong>Severity</strong></td>
<td align="center" valign="center" width="3%">:</td>
<td valign="center" width="57%"><span style="font-size: small;">Remote Compromise (root)</span></td>
</tr>
<tr>
<td valign="center" width="40%"><strong>Author</strong></td>
<td align="center" valign="center" width="3%">:</td>
<td valign="center" width="57%"><span style="font-size: small;">Gary O&#8217;Leary-Steele</span></td>
</tr>
<tr>
<td valign="center" width="40%"><strong>Vendor Status</strong></td>
<td align="center" valign="center" width="3%">:</td>
<td valign="center" width="57%"><span style="font-size: small;">Fixed in 4.2.5</span></td>
</tr>
<tr>
<td valign="center" width="40%"><strong>Website</strong></td>
<td align="center" valign="center" width="3%">:</td>
<td valign="center" width="57%"><span style="font-size: small;">http://www.sec-1.com/blog</span></td>
</tr>
</tbody>
</table>
</td>
</tr>
<tr valign="center">
<td><span style="font-size: small;"><strong><span style="text-decoration: underline;">Vulnerability Summary:</span></strong></span></td>
</tr>
<tr>
<td><span style="font-size: small;">Multiple vulnerabilities were discovered that could be exploited to gain remote code execution as the root/localsystem user. </span><span style="font-size: small;">A full description of the discovered vulnerabilities can be found here: <a href="http://www.sec-1.com/blog/wp-content/uploads/2011/12/Attacking_Splunk_Release.pdf">Download</a><br />
</span></td>
</tr>
<tr>
<td></td>
</tr>
<tr valign="center">
<td><span style="font-size: small;"><strong><span style="text-decoration: underline;">Exploit:</span></strong></span></td>
</tr>
<tr>
<td><span style="font-size: small;"><span style="font-size: small;">Exploit code designed for use in penetration testing can be downloaded here: <a href="http://www.sec-1.com/blog/wp-content/uploads/2011/12/splunkexploit.zip">Download</a></span></span></td>
</tr>
<tr valign="center">
<td><span style="font-size: small;"><strong><span style="text-decoration: underline;">Vendor Response:</span></strong></span></td>
</tr>
<tr>
<td><span style="font-size: small;">The vendor has patched the issue in version 4.2.5. Sec-1 would like to thank Splunk for their prompt and professional response.<br />
</span></td>
</tr>
<tr>
<td></td>
</tr>
<tr valign="center">
<td><span style="font-size: small;"><strong><span style="text-decoration: underline;">Common Vulnerabilities and Exposures (CVE) Information:</span></strong></span></td>
</tr>
<tr>
<td><span style="font-size: small;">The Common Vulnerabilities and Exposures (CVE) project has assigned the following names to these issues. These are candidates for inclusion in the CVE list (http://cve.mitre.org), which standardizes names for security problems.</span></td>
</tr>
<tr>
<td></td>
</tr>
<tr valign="center">
<td><span style="font-size: small;"><strong>CVE : See PDF </strong></span></td>
</tr>
<tr valign="center">
<td></td>
</tr>
<tr align="center" valign="center">
<td><center>Copyright 2011 Sec-1 LTD. All rights reserved.</center></td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.sec-1.com/blog/?feed=rss2&#038;p=233</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sec-1 Penetration Testing Workshop</title>
		<link>http://www.sec-1.com/blog/?p=220</link>
		<comments>http://www.sec-1.com/blog/?p=220#comments</comments>
		<pubDate>Wed, 23 Nov 2011 10:22:44 +0000</pubDate>
		<dc:creator>Gary O'leary-Steele</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.sec-1.com/blog/?p=220</guid>
		<description><![CDATA[Download the slides and supporting tools presented at the Sec-1 Penetration Testing Workshop: <a href="http://www.sec-1.com/blog/?p=220">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Download the slides and supporting tools presented at the Sec-1 Penetration Testing Workshop:</p>
<p><strong>Note:</strong> You will need to obtain the password from your account manager</p>
<p><a title="Slides Only" href="http://www.sec-1.com/blog/wp-content/uploads/2012/02/Sec-1_testing_workshop_0212.zip">Testing Workshop (Slides Only)</a></p>
<p><a title="Slides and Tools" href="https://rapidshare.com/files/4153906647/Sec-1_Seminar.zip">Slides and Tools</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.sec-1.com/blog/?feed=rss2&#038;p=220</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Advisory: WebTitan Multiple Vulnerabilities</title>
		<link>http://www.sec-1.com/blog/?p=211</link>
		<comments>http://www.sec-1.com/blog/?p=211#comments</comments>
		<pubDate>Thu, 20 Oct 2011 15:54:28 +0000</pubDate>
		<dc:creator>waynem</dc:creator>
				<category><![CDATA[Advisories]]></category>

		<guid isPermaLink="false">http://www.sec-1.com/blog/?p=211</guid>
		<description><![CDATA[Sec-1 Security Advisory Advisory Name : WebTitan Multiple Vulnerabilities Release Date : 19/10/2011 Application : WebTitan version 3.50 (Build 183) Platform : VMWare Appliance Severity : SQL injection, Command injection, Dir Traversal Author : Richard Conner Vendor Status : Fixed &#8230; <a href="http://www.sec-1.com/blog/?p=211">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<table style="border-collapse: separate; border-spacing: 0px;" width="640">
<tbody>
<tr valign="center">
<td style="border: none;"><center>Sec-1 Security Advisory</center></td>
</tr>
<tr>
<td style="border: none;">
<table style="border: none; border-collapse: separate; border-spacing: 0px;">
<tbody>
<tr>
<td style="border: none;" valign="center" width="40%"><strong>Advisory Name</strong></td>
<td style="border: none;" align="middle" valign="center" width="3%">:</td>
<td style="border: none;" valign="center" width="57%"><span style="font-size: small;">WebTitan Multiple Vulnerabilities</span></td>
</tr>
<tr>
<td style="border: none;" valign="center" width="40%"><strong>Release Date</strong></td>
<td style="border: none;" align="middle" valign="center" width="3%">:</td>
<td style="border: none;" valign="center" width="57%"><span style="font-size: small;">19/10/2011</span></td>
</tr>
<tr>
<td style="border: none;" valign="center" width="40%"><strong>Application</strong></td>
<td style="border: none;" align="middle" valign="center" width="3%">:</td>
<td style="border: none;" valign="center" width="57%"><span style="font-size: small;">WebTitan version 3.50 (Build 183)</span></td>
</tr>
<tr>
<td style="border: none;" valign="center" width="40%"><strong>Platform</strong></td>
<td style="border: none;" align="middle" valign="center" width="3%">:</td>
<td style="border: none;" valign="center" width="57%"><span style="font-size: small;">VMWare Appliance</span></td>
</tr>
<tr>
<td style="border: none;" valign="center" width="40%"><strong>Severity</strong></td>
<td style="border: none;" align="middle" valign="center" width="3%">:</td>
<td style="border: none;" valign="center" width="57%"><span style="font-size: small;">SQL injection, Command injection, Dir Traversal</span></td>
</tr>
<tr>
<td style="border: none;" valign="center" width="40%"><strong>Author</strong></td>
<td style="border: none;" align="middle" valign="center" width="3%">:</td>
<td style="border: none;" valign="center" width="57%"><span style="font-size: small;">Richard Conner</span></td>
</tr>
<tr>
<td style="border: none;" valign="center" width="40%"><strong>Vendor Status</strong></td>
<td style="border: none;" align="middle" valign="center" width="3%">:</td>
<td style="border: none;" valign="center" width="57%"><span style="font-size: small;">Fixed in Version 3.60</span></td>
</tr>
<tr>
<td style="border: none;" valign="center" width="40%"><strong>Website</strong></td>
<td style="border: none;" align="middle" valign="center" width="3%">:</td>
<td style="border: none;" valign="center" width="57%"><span style="font-size: small;">http://www.sec-1.com/blog</span></td>
</tr>
</tbody>
</table>
</td>
</tr>
<tr valign="center">
<td style="border: none;"><span style="font-size: small;"><strong><span style="text-decoration: underline;">Product Overview:</span></strong></span></td>
</tr>
<tr>
<td style="border: none;"><span style="font-size: small;">Taken from: http://www.webtitan.com/products<br />
<br />
WebTitan is a complete internet monitoring software (web filter) which provides organisations protection for their data from malware and other internet  threats such as viruses, spyware and phishing as well as providing user policy browsing tools to ensure corporate internet policy is adhered  to.</span></td>
</tr>
<tr valign="center">
<td style="border: none;"><span style="font-size: small;"><strong><span style="text-decoration: underline;">Vulnerability  Summary:</span></strong></span></td>
</tr>
<tr>
<td style="border: none;"><span style="font-size: small;">A number of security issues were identified in version 3.50 (Build 183). A SQL injection  attack within the authentication component can be leveraged to recover the password hashes of valid users. Once authenticated access is obtained  further attacks exist. Additional SQL injection, Command Injection providing access to the FreeBSD O/S and a Directory Traversal flaw can be  exploited.</span></td>
</tr>
<tr valign="center">
<td style="border: none;"><span style="font-size: small;"><strong><span style="text-decoration: underline;">Exploit 1: PRE Auth &#8211; Blind SQL  Injection</span></strong></span></td>
</tr>
<tr>
<td style="border: none;"><span style="font-size: small;">The following vulnerability was identified</p>
<p>Login Page: http://172.31.1.25/login.php</p>
<p>This vulnerable component can be accessed without Authenticating. The affected script provides a web interface to the authentication component  of the application. From here it is possible to perform any administrative task includinguser administration and running diagnostics.</p>
<p>Vulnerable Script: /login-x.php</p>
<p>Vulnerable POST request:<br />jaction=login&amp;language=en_US&amp;username=admin&amp;password=hiadmin<br />
Vulnerable Parameter: username<br />Database: POSTGRES</p>
<p>It is possible to perform blind SQL injection within the username parameter to recover the  contents of various tables from the public database, including the admin table which contains the usernames and a MD5 hash of the password for each  administrative account.</span></td>
</tr>
<tr valign="center">
<td style="border: none;"><span style="font-size: small;"><strong><span style="text-decoration: underline;">Exploit 2: POST Auth &#8211; SQL  Injection</span></strong></span></td>
</tr>
<tr>
<td style="border: none;"><span style="font-size: small;">Once Authenticated, either through compromising of the PRE-Auth SQL injection<br />
flaw or through a known administrative account (default values, brute force, etc) it is possible to perform several further SQL injection attacks  against the following;</p>
<p>Vulnerable Script: /urls-x.php</p>
<p>Vulnerable POST Parameters: bldomain, wldomain, temid</span></td>
</tr>
<tr valign="center">
<td style="border: none;"><span style="font-size: small;"><strong><span style="text-decoration: underline;">Exploit 3: POST Auth &#8211; Command  Injection</span></strong></span></td>
</tr>
<tr>
<td style="border: none;"><span style="font-size: small;">The Traceroute or Ping functionality when issued by an authenticated user can be abused to  execute an additional command by the script. Appending two ampersands &amp;&amp; characters to the Ping or Traceroute command causes the script to  execute the instruction as a second command. The returned data is displayed within the diagnostic message within the users web  browser.</p>
<p>Example:</p>
<p>http://172.31.1.25/tools.php#tab0</p>
<p>127.0.0.1 &amp;&amp; cat /etc/passwd</p>
<p>Will display the contents of the  password file which lists the FreeBSD users and their privileges.</span></td>
</tr>
<tr valign="center">
<td style="border: none;"><span style="font-size: small;"><strong><span style="text-decoration: underline;">Exploit 4: POST Auth &#8211; Dir  Traversal</span></strong></span></td>
</tr>
<tr>
<td style="border: none;"><span style="font-size: small;">Example:</p>
<p>http://[HOST_IP]//logs-x.php? jaction=view&amp;fname=../../../../../etc/passwd</span></td>
</tr>
<tr valign="center">
<td style="border: none;"><span style="font-size: small;"><strong><span style="text-decoration: underline;">Vendor  Response:</span></strong></span></td>
</tr>
<tr>
<td style="border: none;"><span style="font-size: small;">These issues were resolved in version 3.60</span></td>
</tr>
<tr valign="center">
<td style="border: none;"><span style="font-size: small;"><strong><span style="text-decoration: underline;">Common Vulnerabilities and Exposures (CVE)  Information:</span></strong></span></td>
</tr>
<tr>
<td style="border: none;"><span style="font-size: small;">The Common Vulnerabilities and Exposures (CVE) project has assigned the following names to  these issues. These are candidates for inclusion in the CVE list (http://cve.mitre.org), which standardizes names for security problems.</span></td>
</tr>
<tr>
<td style="border: none;"> </td>
</tr>
<tr valign="center">
<td style="border: none;"><span style="font-size: small;"><strong>CVE : CVE-2011-4638 (SQL Injection Issues)<br />CVE :  CVE-2011-4639 (POST Auth. Command Injection Issues)<br />CVE : CVE-2011-4640 (POST Auth. Dir Traversal)</strong></span></td>
</tr>
<tr valign="center">
<td style="border: none;"> </td>
</tr>
<tr align="middle" valign="center">
<td style="border: none;"><center>Copyright 2011 Sec-1 LTD. All rights reserved.</center></td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.sec-1.com/blog/?feed=rss2&#038;p=211</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Advisory: Loglogic 5.1 Directory Traversal</title>
		<link>http://www.sec-1.com/blog/?p=113</link>
		<comments>http://www.sec-1.com/blog/?p=113#comments</comments>
		<pubDate>Wed, 06 Jul 2011 08:44:14 +0000</pubDate>
		<dc:creator>Gary O'leary-Steele</dc:creator>
				<category><![CDATA[Advisories]]></category>

		<guid isPermaLink="false">http://www.sec-1.com/blog/?p=113</guid>
		<description><![CDATA[Loglogic 5.1 Directory Traversal.
A directory traversal vulnerability was identified within the Loglogic
web interface. The vulnerability could be exploited by an unauthenticated
attacker to gain access to any file on the local file system. <a href="http://www.sec-1.com/blog/?p=113">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<table style="border-collapse: separate; border-spacing: 0px; " width="640">
<tbody>
<tr valign="center">
<td style="border: none; "><center>Sec-1 Security Advisory</center></td>
</tr>
<tr>
<td style="border: none;">
<table style="border: none; border-collapse: separate; border-spacing: 0px;">
<tbody>
<tr>
<td style="border: none;" valign="center" width="40%"><strong>Advisory Name</strong></td>
<td style="border: none;" align="center" valign="center" width="3%">:</td>
<td style="border: none;" valign="center" width="57%"><span style="font-size: small;">Loglogic 5.1 Directory Traversal</span></td>
</tr>
<tr>
<td style="border: none;" valign="center" width="40%"><strong>Release Date</strong></td>
<td style="border: none;" align="center" valign="center" width="3%">:</td>
<td style="border: none;" valign="center" width="57%"><span style="font-size: small;">06/06/2011</span></td>
</tr>
<tr>
<td style="border: none;" valign="center" width="40%"><strong>Application</strong></td>
<td style="border: none;" align="center" valign="center" width="3%">:</td>
<td style="border: none;" valign="center" width="57%"><span style="font-size: small;">MX3020-PCI Edition / MX Virtual Appliance</span></td>
</tr>
<tr>
<td style="border: none;" valign="center" width="40%"><strong>Platform</strong></td>
<td style="border: none;" align="center" valign="center" width="3%">:</td>
<td style="border: none;" valign="center" width="57%"><span style="font-size: small;">Linux / Appliance</span></td>
</tr>
<tr>
<td style="border: none;" valign="center" width="40%"><strong>Severity</strong></td>
<td style="border: none;" align="center" valign="center" width="3%">:</td>
<td style="border: none;" valign="center" width="57%"><span style="font-size: small;">Remote Compromise (root)</span></td>
</tr>
<tr>
<td style="border: none;" valign="center" width="40%"><strong>Author</strong></td>
<td style="border: none;" align="center" valign="center" width="3%">:</td>
<td style="border: none;" valign="center" width="57%"><span style="font-size: small;">Gary O&#8217;Leary-Steele</span></td>
</tr>
<tr>
<td style="border: none;" valign="center" width="40%"><strong>Vendor Status</strong></td>
<td style="border: none;" align="center" valign="center" width="3%">:</td>
<td style="border: none;" valign="center" width="57%"><span style="font-size: small;">Fixed in HF-3 for version 5.1</span></td>
</tr>
<tr>
<td style="border: none;" valign="center" width="40%"><strong>Website</strong></td>
<td style="border: none;" align="center" valign="center" width="3%">:</td>
<td style="border: none;" valign="center" width="57%"><span style="font-size: small;">http://www.sec-1.com/blog</span></td>
</tr>
</tbody>
</table>
</td>
</tr>
<tr valign="center">
<td style="border:none;"><span style="font-size: small;"><strong><u>Vulnerability Summary:</u></strong></span></td>
</tr>
<tr>
<td style="border:none;"><span style="font-size: small;">A directory traversal vulnerability was identified within the Loglogic web interface. The vulnerability could be exploited by an unauthenticated attacker to gain access to any file on the local file system. For example, the attacker could extract the local /etc/shadow file and launch an offline password attack to recover the root password. Successful exploitation of this vulnerability could provide full control over the affected log management device including any stored reports and log files.</span></td>
</tr>
<tr>
<td style="border:none;">
</td>
</tr>
<tr valign="center">
<td style="border:none;"><span style="font-size: small;"><strong><u>Exploit:</u></strong></span></td>
</tr>
<tr>
<td style="border:none;"><span style="font-size: small;">The following URL will download the /etc/shadow file:</p>
<p>https://[IP]/logapp20/downloadreportzip?file=/../../../../../../../etc/shadow</span></td>
</tr>
<tr valign="center">
<td style="border:none;"><span style="font-size: small;"><strong><u>Vendor Response:</u></strong></span></td>
</tr>
<tr>
<td style="border:none;"><span style="font-size: small;">The vendor has patched the issue in HF-3 for version 5.1</span></td>
</tr>
<tr>
<td style="border:none;">
</td>
</tr>
<tr valign="center">
<td style="border:none;"><span style="font-size: small;"><strong><u>Common Vulnerabilities and Exposures (CVE) Information:</u></strong></span></td>
</tr>
<tr>
<td style="border:none;"><span style="font-size: small;">The Common Vulnerabilities and Exposures (CVE) project has assigned the following names to these issues. These are candidates for inclusion in the CVE list (http://cve.mitre.org), which standardizes names for security problems.</span></td>
</tr>
<tr>
<td style="border:none;">
</td>
</tr>
<tr valign="center">
<td style="border:none;"><span style="font-size: small;"><strong>CVE : CVE-2011-2781 </strong></span></td>
</tr>
<tr valign="center">
<td style="border:none;">
</td>
</tr>
<tr align="center" valign="center">
<td style="border:none;"><span style="font-size: x-small;"><center>Copyright 2011 Sec-1 LTD. All rights reserved.</center></span></td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.sec-1.com/blog/?feed=rss2&#038;p=113</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Advisory: F5 Networks Big-IP Multiple Vulnerabilities</title>
		<link>http://www.sec-1.com/blog/?p=105</link>
		<comments>http://www.sec-1.com/blog/?p=105#comments</comments>
		<pubDate>Mon, 04 Jul 2011 16:42:38 +0000</pubDate>
		<dc:creator>Gary O'leary-Steele</dc:creator>
				<category><![CDATA[Advisories]]></category>

		<guid isPermaLink="false">http://www.sec-1.com/blog/?p=105</guid>
		<description><![CDATA[Sec-1 Security Advisory Advisory Name : F5 Networks Big-IP Multiple Vulnerabilities Release Date : 04/07/2011 Application : F5 Networks Big-IP 10.1.0 Platform : Local Traffic Manager Virtual Edition (tested) Severity : Privilege Escalation (to root), CSRF and XSS Author : &#8230; <a href="http://www.sec-1.com/blog/?p=105">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<table style="border-collapse: separate; border-spacing: 0px; " width="640">
<tbody>
<tr valign="center">
<td style="border: none; "><center>Sec-1 Security Advisory</center></td>
</tr>
<tr>
<td style="border: none;">
<table style="border: none; border-collapse: separate; border-spacing: 0px;">
<tbody>
<tr>
<td style="border: none;" valign="center" width="40%"><strong>Advisory Name</strong></td>
<td style="border: none;" align="center" valign="center" width="3%">:</td>
<td style="border: none;" valign="center" width="57%"><span style="font-size: small;">F5 Networks Big-IP Multiple Vulnerabilities</span></td>
</tr>
<tr>
<td style="border: none;" valign="center" width="40%"><strong>Release Date</strong></td>
<td style="border: none;" align="center" valign="center" width="3%">:</td>
<td style="border: none;" valign="center" width="57%"><span style="font-size: small;">04/07/2011</span></td>
</tr>
<tr>
<td style="border: none;" valign="center" width="40%"><strong>Application</strong></td>
<td style="border: none;" align="center" valign="center" width="3%">:</td>
<td style="border: none;" valign="center" width="57%"><span style="font-size: small;">F5 Networks Big-IP 10.1.0</span></td>
</tr>
<tr>
<td style="border: none;" valign="center" width="40%"><strong>Platform</strong></td>
<td style="border: none;" align="center" valign="center" width="3%">:</td>
<td style="border: none;" valign="center" width="57%"><span style="font-size: small;">Local Traffic Manager Virtual Edition (tested)</span></td>
</tr>
<tr>
<td style="border: none;" valign="center" width="40%"><strong>Severity</strong></td>
<td style="border: none;" align="center" valign="center" width="3%">:</td>
<td style="border: none;" valign="center" width="57%"><span style="font-size: small;">Privilege Escalation (to root), CSRF and XSS</span></td>
</tr>
<tr>
<td style="border: none;" valign="center" width="40%"><strong>Author</strong></td>
<td style="border: none;" align="center" valign="center" width="3%">:</td>
<td style="border: none;" valign="center" width="57%"><span style="font-size: small;">Gary O&#8217;Leary-Steele</span></td>
</tr>
<tr>
<td style="border: none;" valign="center" width="40%"><strong>Vendor Status</strong></td>
<td style="border: none;" align="center" valign="center" width="3%">:</td>
<td style="border: none;" valign="center" width="57%"><span style="font-size: small;">Patch Released</span></td>
</tr>
<tr>
<td style="border: none;" valign="center" width="40%"><strong>Website</strong></td>
<td style="border: none;" align="center" valign="center" width="3%">:</td>
<td style="border: none;" valign="center" width="57%"><span style="font-size: small;">http://www.sec-1.com/blog</span></td>
</tr>
</tbody>
</table>
</td>
</tr>
<tr valign="center">
<td style="border:none;"><span style="font-size: small;"><strong><u>Product Overview:</u></strong></span></td>
</tr>
<tr>
<td style="border:none;"><span style="font-size: small;">Taken from: http://www.f5.com/products/big-ip/ </p>
<p>The BIG-IP product family is a system of integrated application delivery services that work together on the same best-in-class hardware. From load balancing, SSL offload, and web acceleration to application security, access control, and much more, a single BIG-IP device can do the work of a dozen single-purpose appliances.</p>
<p>Local Traffic Manager Virtual Edition enables you to create a mobile, scalable, and adaptable infrastructure for virtualized applications by applying the functionality of BIG-IP LTM in a virtualized environment.</span></td>
</tr>
<tr valign="center">
<td style="border:none;"><span style="font-size: small;"><strong><u>Vulnerability Summary:</u></strong></span></td>
</tr>
<tr>
<td style="border:none;"><span style="font-size: small;">A number of security issues were identified within the management web interface that could be combined to gain unauthorised root access to the affected system. Identified vulnerabilities include Privilege Escalation, Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF/XSRF).</span></td>
</tr>
<tr valign="center">
<td style="border:none;"><span style="font-size: small;"><strong><u>Vulnerability Details</u></strong> &#8211; Privilege Escalation:</span></td>
</tr>
<tr>
<td style="border:none;"><span style="font-size: small;">The following vulnerable script was identified during an analysis of the local file system:</p>
<p>https://[TARGET_IP]/tmui/tools/dbeditor.jsp</p>
<p>To access this component the user must be authenticated to the  web interface as any user (including guest). The affected script provides a web interface to the underlying database along with easy to use templates to change database data. From here it is possible to perform any administrative task including user administration.</p>
<p>From an attackers perspective this interface allows any user, including Guest, to administer any aspect of the Big-IP’s configuration.</span></td>
</tr>
<tr valign="center">
<td style="border:none;"><span style="font-size: small;"><strong><u>Exploit Example 1:</u></strong></span></td>
</tr>
<tr>
<td style="border:none;"><span style="font-size: small;">The following URL, when accessed by any authenticated user will add a root equivalent the user “hacker2? with a password of “admin” to the affected Big-IP system (adds and entry to /etc/shadow):</p>
<p>https://[TARGET_IP]/tmui/tools/commandresults.jsp?sql=INSERT into userdb_entry value(‘hacker2&#8242;,12345,’$1$vj2xXJiEZC0aIA.IBj5rvaEfbDgr0&#8242;,’true’,”,0,0,’/home/hacker2&#8242;,’/bin/sh’,0,”,’false’,&#8217;all’)</p>
<p>This vulnerability could be exploited using common Cross-Site Request forgery techniques such as an embedded IMG tag.</span></td>
</tr>
<tr valign="center">
<td style="border:none;"><span style="font-size: small;"><strong><u>Exploit Example 2:</u></strong></span></td>
</tr>
<tr>
<td style="border:none;"><span style="font-size: small;">The following URL will extract password hashes from the /etc/shadow file:</p>
<p>https://[TARGET_IP]/tmui/tools/commandresults.jsp?sql=select * from userdb_entry</span></td>
</tr>
<tr valign="center">
<td style="border:none;"><span style="font-size: small;"><strong><u>Vulnerability Details</u></strong> &#8211; Cross Site Scripting:</span></td>
</tr>
<tr>
<td style="border:none;"><span style="font-size: small;">Errors returned by the affected script(s) are written to the page without encoding and can therefore be exploited to perform an XSS attack. Furthermore, since the resulting error can be constructed using SQL it is possible to form a payload that will bypass local XSS filters.</span></td>
</tr>
<tr valign="center">
<td style="border:none;"><span style="font-size: small;"><strong><u>Exploit Example 3:</u></strong></span></td>
</tr>
<tr>
<td style="border:none;"><span style="font-size: small;">https://[TARGET_IP]/tmui/tools/commandresults.jsp?sql=select%20name,passwd%20from%20userdb_entry%20union%20select%20%27%3Cscript%3Ealert%281%29%3C/script%3E%27,%27b%27%20from%20userdb_entry</span></td>
</tr>
<tr valign="center">
<td style="border:none;"><span style="font-size: small;"><strong><u>Vendor Response:</u></strong></span></td>
</tr>
<tr>
<td style="border:none;"><span style="font-size: small;">This issue was resolved in version 10.2.2 and within the hotfix release 10.2.1-hf1</span></td>
</tr>
<tr valign="center">
<td style="border:none;"><span style="font-size: small;"><strong><u>Common Vulnerabilities and Exposures (CVE) Information:</u></strong></span></td>
</tr>
<tr>
<td style="border:none;"><span style="font-size: small;">The Common Vulnerabilities and Exposures (CVE) project has assigned the following names to these issues. These are candidates for inclusion in the CVE list (http://cve.mitre.org), which standardizes names for security problems.</span></td>
</tr>
<tr>
<td style="border:none;">
</td>
</tr>
<tr valign="center">
<td style="border:none;"><span style="font-size: small;"><strong>CVE : CVE-2011-3121</strong></span></td>
</tr>
<tr valign="center">
<td style="border:none;">
</td>
</tr>
<tr align="center" valign="center">
<td style="border:none;"><span style="font-size: x-small;"><center>Copyright 2011 Sec-1 LTD. All rights reserved.</center></span></td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.sec-1.com/blog/?feed=rss2&#038;p=105</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tool: Blind SQL Injection exploit tool</title>
		<link>http://www.sec-1.com/blog/?p=47</link>
		<comments>http://www.sec-1.com/blog/?p=47#comments</comments>
		<pubDate>Thu, 27 Jan 2011 16:51:25 +0000</pubDate>
		<dc:creator>Gary O'leary-Steele</dc:creator>
				<category><![CDATA[Tools]]></category>

		<guid isPermaLink="false">http://www.sec-1.com/blog/?p=47</guid>
		<description><![CDATA[Sec-1 Blind Injector (sec1blindinjector.rb) The sec1blindinjector.rb tool is designed to exploit blind SQL injection vulnerabilities in Microsoft SQL Server  based applications. Whilst there are many good tools already out there such as SQLMap, this tool offers a number of unique &#8230; <a href="http://www.sec-1.com/blog/?p=47">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><strong>Sec-1 Blind Injector (sec1blindinjector.rb)</strong></p>
<p>The sec1blindinjector.rb tool is designed to exploit blind SQL injection vulnerabilities in Microsoft SQL Server  based applications. Whilst there are many good tools already out there such as SQLMap, this tool offers a number of unique features we have found useful during penetration testing.</p>
<p><strong>Features</strong></p>
<ul>
<li>Search tables for columns names containing a specific key word (e.g. password)</li>
<li>Search all tables and databases for columns containing specific data (e.g admin)</li>
<li>Enumerate table and column names</li>
<li>Extract table data</li>
<li>Perform a dictionary attack against the local or accessible SQL server (SQL server 2000 only)</li>
<li>Execute operating system commands via cracked &#8220;sa&#8221; account</li>
</ul>
<p>Download here: <a href="http://www.sec-1.com/blog/wp-content/uploads/2011/01/sec1blindinjector.zip">sec1blindinjector</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.sec-1.com/blog/?feed=rss2&#038;p=47</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tool: Identify vulnerable share permissions to prevent data leakage</title>
		<link>http://www.sec-1.com/blog/?p=4</link>
		<comments>http://www.sec-1.com/blog/?p=4#comments</comments>
		<pubDate>Tue, 25 Jan 2011 11:50:02 +0000</pubDate>
		<dc:creator>Gary O'leary-Steele</dc:creator>
				<category><![CDATA[Tools]]></category>

		<guid isPermaLink="false">http://www.sec-1.com/blog/?p=4</guid>
		<description><![CDATA[Sec-1 ShareCheck was written during a penetration test to assess  a given IP Address range for weak file share permissions <a href="http://www.sec-1.com/blog/?p=4">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div class="mceTemp">
<div class="mceTemp">
<p><strong>Windows File Sharing Vulnerabilities</strong></p>
<p><img class="alignleft size-medium wp-image-17" title="Sharecheck Report" src="http://www.sec-1.com/blog/wp-content/uploads/2011/01/report4-300x295.png" alt="" width="300" height="295" />Windows file sharing permissions are based on the popular  Discretionary Access Control (DAC) model, this essentially means that the owner of the resource uses his or her  discretion when deciding who should be permitted access. Access is granted to either an individual user or a group of users, unfortunately file shares are rarely configured with security as a top priority and the course of least resistance is often applied. Vulnerabilities commonly arise when access to a confidential resource is granted to a group containing users who should not permitted to access it, or generalised group such as &#8220;Everyone&#8221; has erroneously been included.</p>
<p><strong> Download: <a href="http://www.sec-1.com/blog/wp-content/uploads/2011/03/sharecheck.zip">ShareCheck</a></strong></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><strong>Sec-1 ShareCheck</strong></p>
<p>Sec-1 ShareCheck was written during a penetration test to assess  a given IP Address range for weak file share permissions. The  output of the tool produces a HTML table containing:</p>
<ul>
<li>The IP Address</li>
<li>Account Lockout Threshold</li>
<li>A list of Local Administrators</li>
<li>Shares which the supplied user can access</li>
<li>Shares which the  supplied user can write to</li>
</ul>
<p>In the course of a penetration test local administrator accounts could then be targeted in an attempt to compromise the host and network.</p>
<p><strong>Usage</strong></p>
<p>ShareCheck is a command line tool written in Python.</p>
<p>To use ShareCheck configure a user account with limited permissions, i.e. a regular user. The results of running ShareCheck will illustrate what this user can and cannot access.</p>
<p>Command line example:</p>
<p>Assess the IP range 192.168.0.1-254 using the username &#8220;Bob&#8221; and the password &#8220;datastealer&#8221; and will save the results in report.html:</p>
<pre>sharecheck.exe 192.168.1.0/24 bob datastealer report.html</pre>
</div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.sec-1.com/blog/?feed=rss2&#038;p=4</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Paper: Buffer Truncation Abuse in Microsoft SQL Server Based Applications</title>
		<link>http://www.sec-1.com/blog/?p=78</link>
		<comments>http://www.sec-1.com/blog/?p=78#comments</comments>
		<pubDate>Fri, 12 Oct 2007 17:27:16 +0000</pubDate>
		<dc:creator>Gary O'leary-Steele</dc:creator>
				<category><![CDATA[White Papers]]></category>

		<guid isPermaLink="false">http://www.sec-1.com/blog/?p=78</guid>
		<description><![CDATA[The document is split into two sections. The first section covers the principals of the technique and the second is an attack case study against a commercial application.

 <a href="http://www.sec-1.com/blog/?p=78">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>This paper is designed to document an attack technique Sec-1 recently adopted during the course of their application assessments. The basic principal of this technique has existed for some time; however we hope this paper we will provide an insight of how a variation of the technique can be adopted to attack common forgotten password functionality within web applications.</p>
<p>The document is split into two sections. The first section covers the principals of the technique and the second is an attack case study against a commercial application.</p>
<p><strong>Download:</strong> <a href="http://www.sec-1.com/blog/wp-content/uploads/2011/01/bta.pdf">Buffer Truncation Abuse Paper</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.sec-1.com/blog/?feed=rss2&#038;p=78</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Advisory: Collaboration Data Objects Buffer Overflow Vulnerability</title>
		<link>http://www.sec-1.com/blog/?p=53</link>
		<comments>http://www.sec-1.com/blog/?p=53#comments</comments>
		<pubDate>Wed, 12 Oct 2005 17:05:56 +0000</pubDate>
		<dc:creator>Gary O'leary-Steele</dc:creator>
				<category><![CDATA[Advisories]]></category>

		<guid isPermaLink="false">http://www.sec-1.com/blog/?p=53</guid>
		<description><![CDATA[                                SEC-1 LTD.                               www.sec-1.com Collaboration Data Objects Buffer Overflow Vulnerability Application: Multiple Applications that implement CDO Platform:Windows Severity: Critical. Remote Code Execution Author: Gary O'leary-Steele Vendor Status:Patch Released CVE Candidate:CAN-2005-1987 Reference:http://www.sec-1.com Disclosed:12/October/2005 Vulnerability Details: Sec-1 has identified an exploitable &#8230; <a href="http://www.sec-1.com/blog/?p=53">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<pre>                                SEC-1 LTD.
                              <a href="http://www.sec-1.com">www.sec-1.com<strong>

</strong></a></pre>
<pre><strong>Collaboration Data Objects Buffer Overflow Vulnerability
Application:</strong> Multiple Applications that implement CDO
<strong>Platform:</strong>Windows
<strong>Severity:</strong> Critical. Remote Code Execution
<strong>Author:</strong> Gary O'leary-Steele
<strong>Vendor Status:</strong>Patch Released
<strong>CVE Candidate:</strong>CAN-2005-1987
<strong>Reference:</strong><a href="http://www.sec-1.com">http://www.sec-1.com</a>
<strong>Disclosed:</strong>12/October/2005</pre>
<pre><strong>Vulnerability Details:</strong>

Sec-1 has identified an exploitable Buffer Overflow within Collaboration Data
Objects (Cdosys.dll and Cdoex.dll). The vulnerability exists when event sinks
are used within Microsoft Exchange 2000 or Microsoft Mail services to parse
Email content. Several Content Security packages were identified to be vulnerable.
The vulnerability can be exploited by crafting an email with a large header
name such as "Content-Type&lt;LARGE STRING&gt;:". A failiure to correctly determine
the length of the string results in a stack overflow. Sucessful exploitation
of the vulnerability could allow the attacker to gain complete control of the
vulnerable host. In somecases the vulnerability can also be used to bypass
content security mechanisms such as virus and content scanners. </pre>
<pre><a href="http://www.microsoft.com/technet/security/bulletin/MS05-048.mspx">http://www.microsoft.com/technet/security/bulletin/MS05-048.mspx
Exploit</a> Download: <a href="http://www.sec-1.com/blog/wp-content/uploads/2011/01/cdo_exploit.zip">cdo_exploit</a></pre>
]]></content:encoded>
			<wfw:commentRss>http://www.sec-1.com/blog/?feed=rss2&#038;p=53</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

