UPDATE: Reading local files in Netscape 6 and Mozilla (GM#001-NS)

From: GreyMagic Software (security@GREYMAGIC.COM)
Date: 05/01/02


Date:         Wed, 1 May 2002 11:09:55 +0200
From: GreyMagic Software <security@GREYMAGIC.COM>
To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM

Hello,

A bit after we released the advisory we received two emails, which notified
us that through testing in our demonstration, they found out that this bug
can also be used to list files in folders.

That alone, makes this bug far more volatile than the one patched by
MS02-008. It is possible to recursively build a tree of the victim's file
system, along with size, date and the content of files.

This vulnerability opens the entire file system up for reading (as long as
the browser user has access).

We added a "Mozilla Disk Explorer" demonstration to our advisory, which lets
you browse through your local disk, entering folders and reading files with
a simple click. Everything you see in this demonstration could be easily
transferred to an attacking server, logging your file system structure and
contents.

You can view it at http://sec.greymagic.com/adv/gm001-ns/mozexplorer.html

Thanks to "loon" and Gerd Zemella for letting us know.

On a different note, this issue has been fixed by the Mozilla crew, thanks
for the quick patch.

        - GMS



Relevant Pages

  • UPDATE (1-May-2002): Reading local files in Netscape 6 and Mozilla (GM#001-NS)
    ... makes this bug far more volatile than the one patched by ... This vulnerability opens the entire file system up for reading (as long as ... We added a "Mozilla Disk Explorer" demonstration to our advisory, ...
    (Bugtraq)
  • Re: I hate to bitch but bitch I must
    ... wanted to point out a bug, the bug means that there is an anomaly under ... much experience reading man pages, and seem to expect them to conform to ... some sort of English Literary standards that are entirely inapplicable. ... You can tune a file system, but you can't tune a fish. ...
    (freebsd-questions)
  • Re: IRP Create
    ... more about the file system and it also showed me that my file system ... Are you listening, Microsoft FS driver ... That bug never manifested itself in the filter sample provided ... Like everything else, the IFS kit slowly is improving, and the mini-filter ...
    (microsoft.public.development.device.drivers)
  • Re: I hate to bitch but bitch I must
    ... > wanted to point out a bug, the bug means that there is an anomaly under ... much experience reading man pages, and seem to expect them to conform to ... some sort of English Literary standards that are entirely inapplicable. ... You can tune a file system, but you can't tune a fish. ...
    (freebsd-questions)
  • Re: the " official point of view" expressed by kernelnewbies.org regarding reiser4 inclusion
    ... Hans Reiser wrote: ... That particular bug isn't in the bitmap scanning code, ... to want a minimum size window was added in June 2004 to 2.6.8-rc2. ... Chinner's high bandwidth file system talk this year at OLS. ...
    (Linux-Kernel)