[VulnWatch] FW: failure notice



Just in case anyone uses IE with Sharepoint.. Boom.

----- Forwarded message from secure@xxxxxxxxxxxxx -----
Date: Tue, 28 Mar 2006 11:47:12 -0800
From: Microsoft Security Response Center <secure@xxxxxxxxxxxxx>
Reply-To: Microsoft Security Response Center <secure@xxxxxxxxxxxxx>
Subject: RE: Another Attack Vector
To: Ken@xxxxxxxxxxxxxx

Hi Ken,

Thanks for getting back to me. I will pass your comments on to the case
manager handling this behavior with the SharePoint team.

Thanks,
Christopher, CISSP

-----Original Message-----
From: Ken@xxxxxxxxxxxxxx [mailto:Ken@xxxxxxxxxxxxxx]
Sent: Tuesday 28 March 2006 11:42
To: Microsoft Security Response Center
Subject: RE: Another Attack Vector

Thank you Christopher,

But there are a bazillion different scenarios where this could be
slightly more than detrimental. There are literally hundreds of sites
using Sharepoint for blogs, and anonymous access is an option turned on
by default. For a real working example, please open the file
IE_Exploit.txt on the below site and watch filemon dance a jig..

Best,
Ken


Quoting Microsoft Security Response Center <secure@xxxxxxxxxxxxx>:

Hi Ken,

Thanks for your note. This is by-design behavior with SharePoint and
Internet Explorer and, as you mentioned, is related to IE MIME type
detection. The mitigating circumstance in this scenario is that
SharePoint sites are authenticated and it would be possible to "audit
and punish" the attacker. Just the same, I'll pass this on to the case

manager for this investigation.

Thanks,
Christopher, CISSP

-----Original Message-----
From: Ken@xxxxxxxxxxxxxx [mailto:Ken@xxxxxxxxxxxxxx]
Sent: Tuesday 28 March 2006 09:16
To: Microsoft Security Response Center
Subject: Another Attack Vector

There is yet another attack vector for createTextRange() (besides
untrusted websites). Windows Sharepoint. If you create a txt file with

html tags and post it, say in "Shared Documents", IE will render it as

HTML in the browser when the document is clicked on instead of
displaying as text. Example:
https://foo.org/Shared%20Documents/test2.txt (code is
simple html here, but could have been dangerous). You might want to
update your advisory to include this.

(And, I know you can de-select "Open Files Based on Content, not file
extension" under IE, but that opens your host to *other*
vulnerabilites.)

Username for the system above for a sample doc is:
testuser with password of password.

Best,
Ken







----- End forwarded message -----



Relevant Pages

  • RE: Documents open as read only on Vista desktops fromo sharepoint sit
    ... SharePoint via IE on Windows Vista, some files are read only, some are ... When you open a document in Word, the document opens as read-only ... Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)
  • Re: ...trying to sip from a firehose...
    ... It's hard to truly get a feel for how SharePoint compares without using it. ... If they have it open for Edit, and another user tries to open it for Edit, ... if a user opens a doc that is already ... like the spreadsheet they thought they were using? ...
    (microsoft.public.sharepoint.windowsservices)
  • Re: People dont like to open an app and have to open a file
    ... I had huge argument with co worker who loved sharepoint by Microsft. ... lets you click on a word or excel doc and it just opens ... sharepoint in a browser, download the fiel to my homedir, and open it ...
    (comp.lang.lisp)
  • Re: Opening an Inserted Object (PDF)
    ... how this Word document was opened (directly from the Sharepoint site ... files - in your case that should be Acrobat. ... What happens incosistantly is that when a user opens the word file ... especially adept at handling PDF files". ...
    (microsoft.public.word.docmanagement)
  • Re: File in SharePoint not being opened by correct application on desktop - IE tries to open it
    ... We want to store files of type obr in SharePoint. ... We have tried going to IIS configuration and adding a new Mime type ... That doesn't seem to work and IE still opens it. ...
    (microsoft.public.sharepoint.windowsservices)