[Full-Disclosure] [SCSA-004] Vulnerability in Microsoft Windows XP

From: Grégory Le Bras | Security Corporation (gregory.lebras@security-corp.org)
Date: 02/19/03

  • Next message: Georgi Guninski: "Re: [Full-Disclosure] Hackers View Visa/MasterCard Accounts"
    From: Grégory Le Bras | Security Corporation <gregory.lebras@security-corp.org>
    To: <full-disclosure@lists.netsys.com>
    Date: Wed, 19 Feb 2003 21:33:59 +0100
    

    .: Vulnerability in Microsoft Windows XP :.

    ________________________________________________________________________

    Security Corporation Security Advisory [SCSA-004]
    ________________________________________________________________________

    PROGRAM: Windows XP
    HOMEPAGE: http://www.microsoft.com
    VULNERABLE VERSIONS: Professionnel & Home
    ________________________________________________________________________

    DESCRIPTION
    ________________________________________________________________________

    Windows XP Microsoft is a operating system of the multinationnale
    Microsoft

    DETAILS
    ________________________________________________________________________

    A vulnerability was found allowing an user of a restricted session to
    have access to private files belonging to any user of the machine,
    also the administrators.

    EXPLOIT
    ________________________________________________________________________

    The exploit is very simple, it is enough to install a httpd Server such
    as ©Apache. Put them on the disc where Windows Microsoft is installed
    as resources of the server. Connect you to the following address:
    http://localhost/
    The index of the disc thus appears to the screen.
    You can then cross the directory /documents and Setting/ and so to reach
    the private files.

    SOLUTIONS
    ________________________________________________________________________

    Compress files mattering with a password.

    VENDOR STATUS
    ________________________________________________________________________

    The vendor has reportedly been notified

    ------------------------------------------------------------
    Tristan aka Timus | http://www.Security-Corp.org
    ------------------------------------------------------------

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html



    Relevant Pages

    • SecurityFocus Microsoft Newsletter #176
      ... MICROSOFT VULNERABILITY SUMMARY ... Microsoft Windows XP HCP URI Handler Arbitrary Command Execu... ... PHPNuke Category Parameter SQL Injection Vulnerability ... Microsoft Baseline Security Analyzer Vulnerability Identific... ...
      (Focus-Microsoft)
    • SecurityFocus Microsoft Newsletter #83
      ... MICROSOFT VULNERABILITY SUMMARY ... Microsoft IIS CodeBrws.ASP Source Code Disclosure Vulnerability ... Microsoft Internet Explorer History List Script Injection ... Microsoft Windows 2000 Lanman Denial of Service Vulnerability ...
      (Focus-Microsoft)
    • SecurityFocus Microsoft Newsletter #242
      ... MICROSOFT VULNERABILITY SUMMARY ... PostNuke Blocks Module Directory Traversal Vulnerability ... Groove Networks Groove Virtual Office COM Object Security By... ... The Microsoft Windows IPV6 TCP/IP stack is prone to a "loopback" condition initiated by sending a TCP packet with the "SYN" flag set and the source address and port spoofed to equal the destination source and port. ...
      (Focus-Microsoft)
    • SecurityFocus Microsoft Newsletter #44
      ... Subject: SecurityFocus Microsoft Newsletter #44 ... MS Visual Studio RAD Support Buffer Overflow Vulnerability ... Microsoft Windows 2000 SMTP Improper Authentication Vulnerability ... Microsoft Windows 2000 Telnet Multiple Sessions DoS Vulnerability ...
      (Focus-Microsoft)
    • SecurityFocus Microsoft Newsletter #77
      ... MICROSOFT VULNERABILITY SUMMARY ... Novell GroupWise Web Root Disclosure Vulnerability ... Microsoft Windows NT Security Policy Bypass Vulnerability ... CVS Server Global Variable Denial Of Service Vulnerability ...
      (Focus-Microsoft)

  • Quantcast