[Full-disclosure] Vulnerabilities in ArcManager



Hello Full-Disclosure!

I want to warn you about security vulnerabilities in ArcManager.

-----------------------------
Advisory: Vulnerabilities in ArcManager
-----------------------------
URL: http://websecurity.com.ua/4057/
-----------------------------
Timeline:
17.03.2010 - found vulnerabilities.
22.03.2010 - disclosed at my site.
23.03.2010 - informed developers.
-----------------------------
Details:

These are Insufficient Anti-automation and Denial of Service
vulnerabilities.

The vulnerabilities exist in captcha script CaptchaSecurityImages.php, which
is using in this system. I already reported about vulnerabilities in
CaptchaSecurityImages (http://websecurity.com.ua/4043/).

Insufficient Anti-automation:

http://site/libs/captcha/CaptchaSecurityImages.php?width=150&height=100&characters=2

Captcha bypass is possible as via half-automated or automated (with using of
OCR) methods, which were mentioned before (http://websecurity.com.ua/4043/),
as with using of session reusing with constant captcha bypass method
(http://websecurity.com.ua/1551/), which was described in project Month of
Bugs in Captchas.

DoS:

http://site/libs/captcha/CaptchaSecurityImages.php?width=1000&height=9000

With setting of large values of width and height it's possible to create
large load at the server.

Vulnerable are all versions of ArcManager.

Best wishes & regards,
MustLive
Administrator of Websecurity web site
http://websecurity.com.ua

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



Relevant Pages

  • Re: Vulnerabilities in Dunia Soccer
    ... disclosure approach for informing admins and web developers about ... But in this time I used responsible full disclosure. ... lists) of vulnerabilities in CaptchaSecurityImages (a captcha script which ... it's single site issue in custom made captcha. ...
    (Bugtraq)
  • Re: [Full-disclosure] Vulnerability in reCAPTCHA for Drupal
    ... full path disclosure IS an information disclosure, ... Vulnerabilities exist at pages:http://site/user/,http://site/user/1/edit, ... reCAPTCHA for Drupal. ... Vulnerable are all versions of reCAPTCHA plugin for Captcha module ...
    (Full-Disclosure)
  • Re: [Full-disclosure] Vulnerability in reCAPTCHA for Drupal
    ... Vulnerabilities exist at pages: http://site/user/, http://site/user/1/edit, ... Every so often he posts a vulnerability of questionable risk in the form of "anti-automation" which is essentially a fancy way of saying "ha ha they don't use CAPTCHA." ... Hosted and sponsored by Secunia - http://secunia.com/ ... Vulnerable are all versions of reCAPTCHA plugin for Captcha module versions ...
    (Full-Disclosure)
  • [Full-disclosure] Vulnerabilities in Drupal
    ... Anti-automation vulnerabilities in Drupal. ... Vulnerable versions of Captcha module are before 6.x-2.3 and 7.x-1.0. ... Vulnerabilities exist at pages: http://site/user/, http://site/user/1/edit, ...
    (Full-Disclosure)
  • Re: Vulnerabilities in Dunia Soccer
    ... - informed developers. ... I don't even know what Dunia soccer is but how about you give vendors a chance to make good? ... Is it a vendor site that has information or is this a informational forum/sale of soccer stuff site that has a buggy captcha that makes the server admin wonder what is chewing up the CPU and why spam is still making it to the site? ... I want to warn you about security vulnerabilities in system Dunia Soccer. ...
    (Bugtraq)