Is there user Anna at your host ?

From: Alexander A. Kelner (akson@tts.debryansk.ru)
Date: 09/12/01


Date: Wed, 12 Sep 2001 18:17:41 +0400 (MSD)
From: "Alexander A. Kelner" <akson@tts.debryansk.ru>
To: <bugtraq@securityfocus.com>
Subject: Is there user Anna at your host ?
Message-ID: <Pine.LNX.4.33.0109121638580.7989-100000@tower.tts.debryansk.ru>


Hi people !

Look here :-)

You have UNIX server www.yourserver.com
You have dozen of usual users at your UNIX server.
You have Apache HTTP daemon configured for standard user's
homepage location at /home/<username>/public_html.

When someone from the Internet tries to see URL like

http://www.yourserver.com/~anna

he gets one of:

1. HTTP result code 200, and Anna's homepage,
   when user "anna" exists at your UNIX, and she has her homepage.

2. HTTP result code 403, and message from Apache:
   "You don't have permission to access /~anna on this server.",
   when user "anna" exists at your UNIX, and she has no homepage
   or access to her homepage is denied.

3. HTTP result code 404, and message from Apache:
   "The requested URL /~anna was not found on this server."
   when user anna doesn't exist at your UNIX.

So, he can easy discover if user "anna" exists at your UNIX,
and try to play with her password, or send her spam etc.

This approach allows him get nesessary info instead of disabled
VRFY feature in your Sendmail !

Apache works quickly and IMHO doesnt provide any responce delays
for any kind of result code. So bad boy can check 1000 different
names for very short time !

Sorry if I'm wrong, or this is something trivial.

A. Kelner



Relevant Pages

  • apache2 lockf process status
    ... I've configured a FreeBSD box with apache 2.0.48 with two sites. ... One for http and the other for https. ... processes were in "lockf" status. ... The fundamental difference between Unix and Macintosh operating system ...
    (comp.unix.bsd.freebsd.misc)
  • Re: Is there user Anna at your host ?
    ... Is there user Anna at your host? ... On some web servers like apache. ... > You have dozen of usual users at your UNIX server. ...
    (Bugtraq)
  • Re: Which Proxy Server...
    ... Apache w/ mod_proxy works fine for http. ... I tried to search Proxy Server for Unix on Internet. ...
    (Security-Basics)
  • Re: NT/2000 vs Unix based Web Servers
    ... There are about a million good reasons to switch. ... easily run Apache on say Red Hat 7.3 on a machine half what you have for IIS ... NT/2000 vs Unix based Web Servers ...
    (Security-Basics)
  • [UNIX] Apache UserDir Information Disclosure (User Anna)
    ... [UNIX] Apache UserDir Information Disclosure (User Anna) ...
    (Securiteam)

Quantcast