[NEWS] Sybex E-Trainer Directory Traversal Vulnerability

From: support@securiteam.com
Date: 02/15/02


From: support@securiteam.com
To: list@securiteam.com
Date: Fri, 15 Feb 2002 03:55:22 +0100 (CET)

The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

When was the last time you checked your server's security?
How about a monthly report?
http://www.AutomatedScanning.com - Know that you're safe.
- - - - - - - - -

  Sybex E-Trainer Directory Traversal Vulnerability
------------------------------------------------------------------------

SUMMARY

 <http://www.sybexetrainer.com/FrontDoor/0,1076,3-23,00.html> Sybex
E-Trainer's are computer based training courses. They run through a web
interface using your web browser. When you launch the course, it loads its
own web server and launches your default web browser that connects to you
locally on the default HTTP server port, 80. When you close your browser,
the web server also shuts down. A security vulnerability in the product
allows remote attackers to traverse and access files that reside outside
the normal bound HTML root directory.

DETAILS

The vulnerability that takes place is the infamous ".." directory
traversal. With a specially crafted request to the web server you can view
any file on the target's computer under the logged in users permissions.
The request is in the format of:

http://target/netget?sid=user&msg=300&file=/../../../filename.ext

The web server only runs when a user runs the e-trainer course. When the
user closes the browser, the web server also shuts down. However if the
user opens the e-trainer and uses the same browser window to start
browsing other websites, the web server will stay open. This could cause
the vulnerable server to continue on running for an even a longer time. It
should also be noted that this web server has not logging features and it
is open to any connection requests. Not just from the local host.

ADDITIONAL INFORMATION

The information has been provided by <mailto:ZeroBreak@softhome.net>
ZeroBreak.

========================================

This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.



Relevant Pages

  • Re: Opening MS Word/XML file generated with javascript
    ... The idea is that it could run off-line in a browser, ... that it opens as a Word file. ... specific HTTP Header in Javascript. ... if I open Word with JScript, there are the security issues again. ...
    (comp.lang.javascript)
  • [NT] Poisoning Cached HTTPS Documents in Internet Explorer
    ... Get your security news from a reliable source. ... "poison" a user's browser cache with a malicious document that will later ... The attacker can exploit this vulnerability for "replacing" HTML ... to communicate with a malicious web server over HTTPS without the browser ...
    (Securiteam)
  • [NT] Webserver 4D Weak Password Preservation Vulnerability
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... complete Web Server environment written entirely on top of 4th Dimension, ... WS4D web server saves the passwords somewhere insecure. ...
    (Securiteam)
  • Re: 2003 Web Server Security flaw
    ... "Locked-down windows 2003 Web Server used only to host web sites". ... What is your logic/rationale for Media Player being a required install ... The Media Player patch was the ONLY that FAILED. ... > When talking about computer security, there are areas that have no such ...
    (microsoft.public.windows.server.security)
  • Web session tracking security prob. Vulnerable: IIS and ColdFusion (maybe others)
    ... SECURITY PROBLEMS WITH WEB SERVERS' SESSION TRACKING MECHANISMS. ... 2001 we reported the following problem (with specifics to IIS and SITESERVER) to the Microsoft Security Response Center. ... These vulnerabilities, especially when combined with well-known cross-site scripting vulnerabilities, could cause loss of confidentiality, failure of non-repudiation and fraud. ... The browser stores and returns the "ASPSESSIONID" or "CFID/CFTOKEN" values with each subsequent request to the web server. ...
    (Vuln-Dev)