[NT] DeepMetrix LiveStats JavaScript Injection
From: support@securiteam.comDate: 06/19/02
- Previous message: support@securiteam.com: "[REVS] Bypassing JavaScript Filters - the Flash! Attack"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: support@securiteam.com To: list@securiteam.com Date: Wed, 19 Jun 2002 09:12:41 +0200 (CEST)
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
When was the last time you checked your server's security?
How about a monthly report?
http://www.AutomatedScanning.com - Know that you're safe.
- - - - - - - - -
DeepMetrix LiveStats JavaScript Injection
------------------------------------------------------------------------
SUMMARY
DeepMetrix (formerly MediaHouse) LiveStats is server software that
provides an interactive web based summary of website traffic based on HTTP
server logs. A security vulnerability in the product allows attackers to
insert malicious JavaScript and HTML into existing web pages.
DETAILS
Vulnerable systems:
* LiveStats versions between 5.03 and 6.2.1
By crafting special user-agent or referer headers on HTTP requests to a
web site that is monitored by LiveStats, arbitrary JavaScript can be
executed in the browser of a person viewing the LiveStats HTML reports.
LiveStats displays the browser-tag and referer strings in its reports
verbatim, including any script tags. Script that discloses the URL of the
LiveStats interface could allow access that is normally protected by a
private ServerID.
Demonstration:
Browse <http://www.deepmetrix.com/> http://www.deepmetrix.com/ with a
user-agent of XXX<script>alert("foo");</script> Then browse the Demo of
LiveStats available on the DeepMetrix web site at:
<http://livestats.deepmetrix.com/stats?type=login&action=login&serverid=deepmetrix&username=guest> http://livestats.deepmetrix.com/stats?type=login&action=login&serverid=deepmetrix& username=guest
In the "Tabular - Who's On - XX Active Visitors" area of the "Who's On"
page, expand the IP address that fetched. The next window will include the
alert() popup.
Vendor status:
The vendor was notified on the 17th of May 2002.
ADDITIONAL INFORMATION
The information has been provided by <mailto:security@satus.com> Daniel
Bowers.
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Previous message: support@securiteam.com: "[REVS] Bypassing JavaScript Filters - the Flash! Attack"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
- [NT] Vulnerability in Exchange Server 5.5 Outlook Web Access Could Allow Cross-Site Scripting Attack
... The following security advisory is sent to the securiteam mailing list, and can be found at
the SecuriTeam web site: http://www.securiteam.com ... Get your security news from
a reliable source. ... * Microsoft Exchange 2000 Server ... An attacker could seek
to exploit this vulnerability by having a user run ... (Securiteam) - Re: Urgent: Problem setting up web site hosting on SBS03 with ISA
... hosting our own web site on the SBS box will be a temporary solution. ... the
owner that he understood the security risks. ... comapny that interacts with information
in the local SQL Server. ... Internet Control Message Protocol ... (microsoft.public.windows.server.sbs) - Re: Directory security
... > The IWAM_webhost72 account will need to have Read and Execute access to ...
>> Subject: Directory security ... >> I host multiple sites on one server.
... >> Then I set up a new user for a particular web site and put ... (microsoft.public.inetserver.iis.security) - Re: Urgent: Problem setting up web site hosting on SBS03 with ISA
... the security concerns are real and it would worry me even more ... running ASP
stuff with a connection to the SQL that sits on the same box. ... The web site needs
to be running locally (instead of hosted on the ISP's ... comapny that interacts with information
in the local SQL Server. ... (microsoft.public.windows.server.sbs) - Re: IUSR trying to run cmd.exe... who is it?
... Ensure your server is up to date. ... > Event Source: Security ...
> Client User Name: - ... > Any ideas on how to detect which web site is doing
this?? ... (microsoft.public.inetserver.iis.security)