[UNIX] ChangshinSoft ezTrans Server File Download Vulnerability

From: SecuriTeam (support_at_securiteam.com)
Date: 07/08/03

  • Next message: SecuriTeam: "[EXPL] Yahoo Messenger Service Call Buffer Overflow Vulnerability Resurfaces"
    To: list@securiteam.com
    Date: 8 Jul 2003 15:25:40 +0200
    
    

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    Beyond Security in Canada

    Toronto-based Sunrays Technologies is now Beyond Security's representative in Canada.
    We welcome ISPs, system integrators and IT systems resellers
    to promote the most advanced vulnerability assessment solutions today.

    Contact us at 416-482-0038 or at canadasales@beyondsecurity.com

    - - - - - - - - -

      ChangshinSoft ezTrans Server File Download Vulnerability
    ------------------------------------------------------------------------

    SUMMARY

     <http://cssoft.co.kr/jp/solutions01.html> ezTrans Server, used by famous
    portal sites in Korea, is "a real-time Korean-to-Japanese and
    Japanese-to-Korean translator made by ChangshinSoft". Due to inappropriate
    input validation in a file download module of ezTrans Server, an attacker
    can download any file that is accessible to web server's privileges.

    DETAILS

    Proof of Concept:
    http://[victim
    site]/question/crm/download.php?filename=../../../../../../../../../../../../etc/passwd

    http://[victim
    site]/download.php?filename=../../../../../../../../../../../../../etc/passwd

    Workaround:
    To minimize the effects of this vulnerability, we recommend following
    workarounds.

    1. Turn register_globals option in php.ini OFF. For detailed information,
    refer to below sites.
    2. Delete the vulnerable download.php and use static link to a file to
    download inside your HTML source.

    Vendor status:
    2003-06-24 CSSoft notified.
    2003-06-26 Second attempt to contact the vendor and system administrator.
    2003-07-02 Third attempt to contact the vendor contact.
    2003-07-04 Forth attempt to contact the vendor contact.
    2003-07-04 Vendor replied.
    2003-07-04 Last attempt to contact the vendor contact.
    2003-07-04 Vendor issued a fix.
    2003-07-08 Public disclosure.

    ADDITIONAL INFORMATION

    The information has been provided by <mailto:advisory@stgsecurity.com>
    Jeremy Bae at STG Security SSR Team.

    ========================================

    This bulletin is sent to members of the SecuriTeam mailing list.
    To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
    In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

    ====================
    ====================

    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any kind.
    In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.


  • Next message: SecuriTeam: "[EXPL] Yahoo Messenger Service Call Buffer Overflow Vulnerability Resurfaces"

    Relevant Pages

    • [NEWS] Wonderware SuiteLink Denial of Service Vulnerability
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... Vendor Information, Solutions and Workarounds ... Core sends the advisory draft to Wonderware support team. ...
      (Securiteam)
    • [Full-Disclosure] Security Industry Under Scrutiny: Part 3
      ... > varying degrees of 'faith' in the security industry. ... site admins and other whitehats. ... > architect would be notifying the software vendor alone... ... Full disclosure isn't so much a tool to get vunerability information ...
      (Full-Disclosure)
    • [NT] Internet Explorer Zone Elevation Restrictions Bypass and Security Zone Restrictions Bypass (MS0
      ... Get your security news from a reliable source. ... Internet Explorer Zone Elevation Restrictions Bypass and Security Zone ... Vendor Information, Solutions and Workarounds: ... Core sends an advisory ...
      (Securiteam)
    • RE: Vendor wants remote control of our Servers and Workstations
      ... Of course the age-old problem with security is that ... Vendor has significant access to your internal ... this vendor uses the same method to support a number ... customer and makes significant changes ... ...
      (Security-Basics)
    • Security researchers organization
      ... of security researchers, plain and simple. ... better than the vendor itself. ... industry, telecommunications industry and banking industry has ( ... These are all common ideals we can agree and act upon, ...
      (NT-Bugtraq)