Webmin 1.050 - 1.060 remote exploit

From: Carl Livitt (carl@learningshophull.co.uk)
Date: 02/24/03

  • Next message: FreeBSD Security Advisories: "FreeBSD Security Advisory FreeBSD-SA-03:03.syncookies"
    From: Carl Livitt <carl@learningshophull.co.uk>
    To: bugtraq@securityfocus.com
    Date: Mon, 24 Feb 2003 12:45:43 +0000
    
    
    

    Hi all,

    Attached is an exploit for the latest Webmin vulnerability. It relies on a
    non-default setting (passdelay) to be enabled.

    Webmin can verify user authentication by use of a session ID (SID) that is
    assigned when a user successfully authenticates to Webmin. It is possible to
    inject a fake SID into the session ID database by using a malicious username
    containing control sequences used internally by Webmin.

    This exploit simply creates a SID of 1234567890 for the user 'admin'. Then, it
    is a simple case of creating a cookie in your favorite browser containing:

    sid=1234567890; testing=1

    Such that the Cookie HTTP header contains:

    Cookie: sid=1234567890; testing=1

    When the webmin server recieves this cookie, it is verified as an authentic
    SID and an attacker can take complete control of the Webmin server... this is
    basically root access to the box it is running on.

    Cheers,
    Carl

    
    




    Relevant Pages

    • [SNS Advisory No.83] Webmin/Usermin PAM Authentication Bypass Vulnerability
      ... Usermin to run. ... Webmin is a web-based system administration tool for Unix. ... PAM(Pluggable Authentication Modules) authentication process. ... This SNS Advisory is being published in coordination with Information-technology ...
      (Bugtraq)
    • [SNS Advisory No.52] Webmin/Usermin Cross-site Scripting Vulnerability
      ... Webmin/Usermin Cross-site Scripting Vulnerability ... The authentication page of both Webmin and Usermin is prone to a ... Webmin is a web-based system administration tool for Unix. ... the authentication page used by both Webmin and Usermin, ...
      (Bugtraq)
    • Re: Debian as a Web server
      ... cPanel and Plesk plus others have support for the stable versions of ... Debian (cPanel even still supports Woody, ... There is also webmin, which keeps up quite nicely even with Sid, IIRC. ...
      (Debian-User)
    • Point missed. Was: Re: Debian as a Web server
      ... Debian (cPanel even still supports Woody, ... There is also webmin, which keeps up quite nicely even with Sid, IIRC. ... but they still do support Debian. ...
      (Debian-User)
    • Re: Debian as a Web server
      ... Debian (cPanel even still supports Woody, ... There is also webmin, which keeps up quite nicely even with Sid, IIRC. ... but they still do support Debian. ...
      (Debian-User)