Outlook Web Access authentication bypass

From: Chris Robertson (Chris.Robertson_at_instill.com)
Date: 05/23/03

  • Next message: Paul Szabo: "Eudora 5.2.1 buffer overflow DoS"
    To: "'bugtraq@securityfocus.com'" <bugtraq@securityfocus.com>
    Date: Fri, 23 May 2003 01:03:17 -0700
    
    

    This exploit exhibits the same symptoms as CAN-2002-0507 however I have
    found it is possible on an Exchange 5.5 (patches current to within ~3
    months) single system Outlook Web Access install (IIS and Exchange on the
    same server) to access any mailbox once the client has been successfully
    authenticated in Netscape 7.0 on Windows 2k and Redhat 7.2, Mozilla 1.0.1,
    Galeon 1.2.5, and Konqueror 3.0.3-13 on Redhat 8.0. Additionally under IE
    5.50.4807.2300 it is possible to get the same behavior by canceling an
    attempted login to a non-authorized mailbox and editing the url from
    ..."isnewwindow=0"... to ..."isnewwindow=1"...

    Does anyone have anymore info on this?

    Thanks,
    Chris Robertson
    Security Engineer
    Instill Corp.


  • Next message: Paul Szabo: "Eudora 5.2.1 buffer overflow DoS"

    Relevant Pages

    • RE: Vista Business (32 Bit) and Outlook Web Access - need help!
      ... Ensure Exchange SP2 is installed on the server. ... If Exchange 2003 SP2 is not installed on the server, ... The URLScan tool may cause problems in Outlook Web Access ... IIS Lockdown and URLscan Configurations in an Exchange Environment ...
      (microsoft.public.windows.server.sbs)
    • RE: Exchange doesnt send mails in pickup-folder
      ... Message Filter in Exchange Server 2003. ... Gateway level and Store ... If Intelligent Message Filter assigns the message an SCL rating that is ... If a user is using Outlook 2003 or Outlook Web Access with Exchange ...
      (microsoft.public.windows.server.sbs)
    • Re: Accessing Outlook Calendar & Contacts Remotely
      ... using Exchange, you cannot use Outlook Web Access. ... Google Calendar ... Tim wrote: ... What is RWW and Outlook Web Access? ...
      (microsoft.public.windows.server.sbs)
    • Re: Outlook xp home edition and outlook web access inbox
      ... change her email from a pst to the exchange mailbox, ... her email from her inbox to the mailbox. ... >> I could just have her use outlook web access, ... >> mode, folder redirection, and xp home edition. ...
      (microsoft.public.windows.server.sbs)
    • Re: Recommendations for Installing Exchange
      ... Outlook Web Access, right? ... with Exchange 2003 will I be able to allow ... >they could use their own ISP's SMTP server for outbound ... >> get it to require authentication when accepting mail ...
      (microsoft.public.exchange.setup)