Re: TA-2003-06 Directory Transversal Vulnerability in iWeb Server 2

Rushjo_at_tripbit.org
Date: 06/27/03

  • Next message: dreamer_at_darkness.gr: "Bahamut DoS"
    Date: Fri, 27 Jun 2003 18:59:50 +0200
    To: bugtraq@securityfocus.com
    
    

    Hi akcess,

    thx for your feedback. But not all of your comments are right.
    First I wrote this in the advisory:

    [qoute]
    The vendor has reportedly been notified. But the vendor told us that is
    an old bug. We don't think so.
    [/ qoute]

    Alright perhaps next time it will be better to mention the url of the
    old bug. And of course it is an "another form of the old bug" but did
    you really read the old advisory? For example the recommended solution?

    [quote]
    * taken from http://securityfocus.com/archive/1/318775 *

    .....:[ Vendor Status :

    14/04/03 Initial Contact Made
    15/04/03 Vendor Responded
    15/04/03 Vendor Released Updated Version

    .....:[ Solution :

    Remove old iWeb application and download and install the updated
    version which can be found at:

    http://ashleybrown.co.uk/downloads/iws2.exe
    [/qoute]

    And this is the point. We tested the "safe" iWeb Server2 and still found
    this bug. So we don't think that it is fixed. Because of the reaction of
    the vendor we deceided to post this here.

    And of course thanks for hints to posidron's "work". He "rebuilded" this
    tool with the help of your hints.

    Have a lot of fun

    Rushjo


  • Next message: dreamer_at_darkness.gr: "Bahamut DoS"

    Relevant Pages

    • Re: Reading local files in Netscape 6 and Mozilla (GM#001-NS)
      ... >bugzilla entry on bugzilla.mozilla.org which is the best place for bug ... This inconsistency can make it difficult for vulnerability reporters ... to contact the vendor, and some reporters feel forced to publicly ...
      (NT-Bugtraq)
    • [VulnWatch] RE: [VulnDiscuss] new IE bug (confirmed on ALL windows)
      ... choose to work with a vendor. ... VulnWatch has never attempted to impose any type of disclosure policy on ... VulnWatch will gladly help any researcher or casual IT Security ... before anyone has offered to pay you "beer money" for a bug. ...
      (VulnWatch)
    • Re: Complicated Disclosure Scenario
      ... Forward your vuln-dev letter to them, informing them of your dilemma; ... I say give them one last chance or else post the advisory; ... Initially the bug presented itself as a way to ... > I informed this vendor, who is by no means short on resources, that I ...
      (Vuln-Dev)
    • RE: Complicated Disclosure Scenario
      ... Vendor stonewalling is the reason full disclosure got started, ... Subject: Complicated Disclosure Scenario ... basically, if they refuse to acknowledge the bug, and the bug exists in a ...
      (Vuln-Dev)
    • RE: Complicated Disclosure Scenario
      ... I would contact someone like the vuln-help folks at security focus, CERT, ... supposed to be) can step in and club the vendor until they get a clue. ... Initially the bug presented itself as a way to ... before they began creating an advisory or even working on a patch. ...
      (Vuln-Dev)