Re: PCL-0001: Remote Vulnerability in HORDE MTA < 2.2.4

From: Ricardo J. Ulisses Filho (ricardoj_at_hotlink.com.br)
Date: 08/15/03

  • Next message: weigelt_at_metux.de: "Re: Buffer overflow prevention"
    To: Vincenzo 'puccio' Ciaglia <puccio@pucciolab.org>
    Date: Fri, 15 Aug 2003 12:35:25 -0300
    
    

    Hi,

    I've made some tests here and could reproduce the same vulnerability behaviour
    described in your advisory.
    Reading about session handlers, in php.ini, there is an option called
    "session.use_only_cookies", that, if set, avoids such sort of attack which
    involves passing session ids in URLs.
    Unfortunately, this option is not used by most default php.ini configurations.

    Regards,

    -- 
    Ricardo J. Ulisses Filho
    _____________________________
    ricardoj@hotlink.com.br
    System Administrator
    HOTlink Internet - Recife / PE /  Brazil
    On Wednesday 13 August 2003 18:26, Vincenzo 'puccio' Ciaglia wrote:
    > ---------------------------
    > PUCCIOLAB.ORG - ADVISORIES
    > <http://www.pucciolab.org>
    > ---------------------------
    >
    > PCL-0001: Remote Vulnerability in HORDE MTA < 2.2.4
    >
    > ---------------------------------------------------------------------------
    > PuCCiOLAB.ORG Security Advisories                      puccio@pucciolab.org
    > http://www.pucciolab.org                          Vincenzo 'puccio' Ciaglia
    > August 12th, 2003
    > ---------------------------------------------------------------------------
    >
    > Package        : Horde MTA
    > Vulnerability  : access to private account without login
    > Problem-Type   : remote
    > Version        : All < 2.2.4
    > Official Site  : http://horde.org/
    > N° Advisories  : 0001
    >
    > ***********************
    > Description of problem
    > ************************
    > An attacker could send an email to the victim who ago use of HORDE MTA in
    > order to push it to visit a website. The website in issue log all the
    > accesses and describe in the particular the origin of every victim.
    >
    > Example:
    > -------------------
    > MY STAT FOR MY WEBSITE - REFERENT DOMAIN
    > http://MYSITE.MYSOCIETY.NET/HORDE/IMP/MESSAGE.PHP?HORDE=FC235847D2C8A88190C
    >879B290D12630&INDEX=XXX
    >
    > In this example, the victim has visualized our website reading the mail
    > that we have sent to it. Visiting the link marked from our counter of
    > accesses, we will be able to approach the page of management of the mail of
    > the victim and will be able to read and to send, calmly, its email without
    > to make the login.The session comes sluice after approximately 20 minutes
    > and the hacker it has the time to make its comfortable ones.
    >
    > *************************
    > What could make a attacker?
    > *************************
    > Read, write and fake your e-mail. Could send , from you email address, a
    > mail to your ISP and ask it User e PASS of your website.The consequences
    > would be catastrophic
    >
    > *************************
    > What I can do ?
    > *************************
    > Upgrade your MTA Agent to 2.2.4 version.
    >
    > Greet,
    > Vincenzo 'puccio' Ciaglia
    > www.pucciolab.org
    

  • Next message: weigelt_at_metux.de: "Re: Buffer overflow prevention"

    Relevant Pages

    • Secure website (cookie/session)
      ... Secure a part of my website. ... access to server settings (session timeout, security,...). ... do not lose time re-submitting it because the use was redirect to the ...
      (microsoft.public.inetserver.iis.security)
    • Secure website (cookie/session)
      ... Secure a part of my website. ... access to server settings (session timeout, security,...). ... do not lose time re-submitting it because the use was redirect to the ...
      (microsoft.public.inetserver.iis.security)
    • Re: Need Advice on Wireless internet bill paying while boondocking
      ... you're 'in the middle' of the transmission path for the session. ... victim to these complicated ruses. ... bad guy 'intercepts' that command on the wire, doesn't reach secure site.. ... bad guy echoes response to real secure-site server. ...
      (rec.outdoors.rv-travel)
    • Re: NTLM/Browser Storing Any Sessions ??
      ... I'm not sure why sounds like the session was still ... Enabled for all Internet Website. ... Authentication Prompt(it could be the server has been enabled with the ... the authentication to the Intranet Website also? ...
      (microsoft.public.inetserver.iis.ftp)
    • Re: WSE 2.0 1000 Foot level Question Easy one
      ... I can Use SecureConversation between the Website and the WebService ... I can keep that info in a session variable, ... Passing the user account and password to the web service so the web ...
      (microsoft.public.dotnet.framework.webservices.enhancements)