[NT] Multiple Vulnerabilites in Aldos Webserver

From: SecuriTeam (support_at_securiteam.com)
Date: 05/04/04

  • Next message: SecuriTeam: "[NT] Dameware Mini Remote Control Weak Key Agreement Scheme"
    To: list@securiteam.com
    Date: 4 May 2004 17:11:32 +0200
    
    

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    The SecuriTeam alerts list - Free, Accurate, Independent.

    Get your security news from a reliable source.
    http://www.securiteam.com/mailinglist.html

    - - - - - - - - -

      Multiple Vulnerabilites in Aldos Webserver
    ------------------------------------------------------------------------

    SUMMARY

     <http://aldostools.mysite4now.com/aweb.html> Aldo's Web Server is "a
    super-compact Web service daemon that not only let you share easily your
    files, it also acts as a Advertisement or site blocker". The product has
    been found to contain two security vulnerabilities, one allowing gaining
    of sensitive information on the remote computer, the other allows
    accessing of files that reside outside the bound HTML root directory.

    DETAILS

    Vulnerable Systems:
     * Aldos Web Server version 1.5

    Physical Path Disclosure:
    Connecting to Aweb via Telnet/Netcat, and entering any character will lead
    to an output similar to this: "Oliver_karow||D:\webserverMAI\aweb\"

    Whereby oliver_karow is the user that runs the web server process.
        
    Directory Traversal:
    Connecting to Aweb via Telnet/Netcat, and requesting a file like "GET
    /../../../boot.ini HTTP/1.0" enables an attacker to get access to files
    outside of the webroot folder.

    ADDITIONAL INFORMATION

    The information has been provided by <mailto:oliver@greyhat.de> Oliver
    Karow.

    The original article can be found at:
    <http://www.oliverkarow.de/research/AldosWebserverMultipleVulns.txt>
    http://www.oliverkarow.de/research/AldosWebserverMultipleVulns.txt

    ========================================

    This bulletin is sent to members of the SecuriTeam mailing list.
    To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
    In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

    ====================
    ====================

    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any kind.
    In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.


  • Next message: SecuriTeam: "[NT] Dameware Mini Remote Control Weak Key Agreement Scheme"

    Relevant Pages

    • [NT] PMSoftware Simple Web Server Buffer Overflow
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... HTTP Web Server" ... The information in this bulletin is provided "AS IS" without warranty of any kind. ... In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages. ...
      (Securiteam)
    • [UNIX] PHP / Apache DoS (Resource Consumption)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... PHP and Apache based hosting is becoming very popular these days. ... of service attack against the web server can be created using a very ...
      (Securiteam)
    • [NT] PeopleSoft PeopleBooks Search CGI Multiple Argument Issues
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... - Cause a Denial of Services on the web server host. ... PeopleSoft have released details of this and other issues under security ...
      (Securiteam)
    • [EXPL] TinyWeb Server DoS Exploit
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... The information in this bulletin is provided "AS IS" without warranty of any kind. ... In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages. ...
      (Securiteam)
    • [UNIX] SquirrelMail Cross Site Scripting in Encoded Text
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... SquirrelMail has all the functionality you would want from an email ... In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages. ...
      (Securiteam)