(no subject)

From: Tristan Brotherton (Tris@FLUIDJUICE.COM)
Date: 02/06/02


Date:         Wed, 6 Feb 2002 12:26:18 -0000
From: Tristan Brotherton <Tris@FLUIDJUICE.COM>
To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM

Russ,

Thanks for your pointers, below is my reply: :)

All,

 I started to play with MS siteserver, for content management on some of
our systems. I was a bit horrified, that with a default install it
installs an ASP file called "viewsource.asp" that, surprise surprise
allows you to view the source code for any ASP / server based files on
that site.

By default, this means a well educated "user" could gain source access,
and possible database passwords to any page on your website.

Needless to say after the default install I got rid of it. It normally
resides in: http://SERVER/SiteServer/Publishing/viewcode.asp

It will remain on this URL if you follow the default site server setup

Simply pass it a URL and it will show you full source. IE:

http://SERVER/SiteServer/Publishing/viewcode.asp?source=/PAGETODISPLAY.a
sp

Surely no big commercial company would leave this nasty little asp page
running?

Well, I had a quick check on several Microsoft run sites, and gained
full access to their sites source code / content management systems. I
have since informed the concerned parties, and the scripts have been
removed.

Solution - CHECK YOUR SITESERVER install for viewsource.asp If a default
install has taken place REMOVE the sample sites. Check this by viewing
http://SERVER/SiteServer/ to see if any pages are displayed.

<start dig at ms> I find it worrying that this file is installed with NO
PERMISSIONING allowing full access to private data on the system. I also
find it worrying the writers themselves didn't notice the adverse
affects when installing it on their own systems </end dig at ms>

Tristan Brotherton Fluidjuice Digital
Tris@fluidjuice.com

- peace, love and bandwidth-

Tristan Brotherton

Founder and Director - Fluidjuice Digital

Web: www.fluidjuice.com
Email: Tris@fluidjuice.com

oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo
Delivery co-sponsored by Qualys - Make Your Network Secure
oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo
Go Beyond PARTIAL Security: FREE White Paper

Stop hassling with half-baked ENTERPRISE SECURITY.
FREE White Paper shows you how to ensure TOTAL security for your Internet
perimeter with the most current and most complete PROACTIVE Vulnerability
Assessment solution. Get your FREE White Paper now. Click here!
https://www.qualys.com/forms/techwhite_86.html
oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo



Relevant Pages

  • Re: Video editing in Linux?
    ... >> this is an absolute world of difference from windows. ... but theres so much to take in just to install an audio app. ... I was under the impression that you sent the source code and a patch ...
    (alt.linux)
  • Re: whats a callback?
    ... That's because you get all the source code and about 3000 other ... > for instance PocketPC Windows doesn't take up that much space either. ... What about the fact that Excel ... will be available after the install of the next MS Office Service Pack. ...
    (comp.arch.embedded)
  • Re: whats a callback?
    ... That's because you get all the source code and about 3000 other ... > for instance PocketPC Windows doesn't take up that much space either. ... What about the fact that Excel ... will be available after the install of the next MS Office Service Pack. ...
    (sci.electronics.design)
  • [HPADM] SUMMARY: less getting "WARNING: terminal is not fully functional"
    ... Inspection of the less source code suggests that is it missing termcap ... The box in question is a relatively fresh install of 11.23 HP-UX on ia64 ... Itanium servers. ... but then you will have to compile your own less binaries. ...
    (HP-UX-Admin)
  • Re: Linux Vs. FreeBSD
    ... On the other hand, compiling ... >> source code is annoyingly slow and relatively difficult when it cones ... > different architectures and environments, ... install it in a matter of seconds or minutes, ...
    (comp.os.linux.misc)