UPDATE: Reading local files in Netscape 6 and Mozilla (GM#001-NS)

From: GreyMagic Software (security@GREYMAGIC.COM)
Date: 05/01/02


Date:         Wed, 1 May 2002 11:09:55 +0200
From: GreyMagic Software <security@GREYMAGIC.COM>
To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM

Hello,

A bit after we released the advisory we received two emails, which notified
us that through testing in our demonstration, they found out that this bug
can also be used to list files in folders.

That alone, makes this bug far more volatile than the one patched by
MS02-008. It is possible to recursively build a tree of the victim's file
system, along with size, date and the content of files.

This vulnerability opens the entire file system up for reading (as long as
the browser user has access).

We added a "Mozilla Disk Explorer" demonstration to our advisory, which lets
you browse through your local disk, entering folders and reading files with
a simple click. Everything you see in this demonstration could be easily
transferred to an attacking server, logging your file system structure and
contents.

You can view it at http://sec.greymagic.com/adv/gm001-ns/mozexplorer.html

Thanks to "loon" and Gerd Zemella for letting us know.

On a different note, this issue has been fixed by the Mozilla crew, thanks
for the quick patch.

        - GMS



Relevant Pages

  • UPDATE (1-May-2002): Reading local files in Netscape 6 and Mozilla (GM#001-NS)
    ... makes this bug far more volatile than the one patched by ... This vulnerability opens the entire file system up for reading (as long as ... We added a "Mozilla Disk Explorer" demonstration to our advisory, ...
    (Bugtraq)
  • Re: IRP Create
    ... more about the file system and it also showed me that my file system ... Are you listening, Microsoft FS driver ... That bug never manifested itself in the filter sample provided ... Like everything else, the IFS kit slowly is improving, and the mini-filter ...
    (microsoft.public.development.device.drivers)
  • Re: the " official point of view" expressed by kernelnewbies.org regarding reiser4 inclusion
    ... Hans Reiser wrote: ... That particular bug isn't in the bitmap scanning code, ... to want a minimum size window was added in June 2004 to 2.6.8-rc2. ... Chinner's high bandwidth file system talk this year at OLS. ...
    (Linux-Kernel)
  • Suse 9.3 repair from CD/DVD is buggy!
    ... /dev/hda3 is / with an xfs file system. ... "No valid root partition was found, probably there is no valid linux system ... Customized install that I used to create this system....and either ... But released versions should be as much as possible free of major bug. ...
    (alt.os.linux.suse)
  • Snapshots fail on busy filesystem
    ... I get this same problem completely at random, and thus is most likely caused by the busy file system, I just don't have anything in place to prove it as the bug submitter does. ... My primary goal is to make sure that I have a good backup of the databases running on our servers when we run a backup with Bacula. ... If there is a method other than snapshots to make absolutely sure that my databases are backed up correctly, I would consider that as well. ...
    (freebsd-questions)