|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
Re: More info on MS99-061 (IIS escape character vulnerability)
Subject: Re: More info on MS99-061 (IIS escape character vulnerability)
From: Joakim Karlmark (joakim.karlmark
PDKONSULT.COM)
Date: Sun Jan 02 2000 - 05:51:50 CST
- Next message: Justin Tripp: "HPUX Aserver revisited."
- Previous message: John Archie: "Re: majordomo local exploit"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
> What does this allow you to bypass? My guess is anything that plays or
> needs the raw filename or request. ISAPI filters and extension handlers
> come to mind. Who, what, where, and how are application specific.
One category of systems that are vulnerable to this are
3rd party authentications modules that do, for example radius
authentication.
One system that I've checked uses a special directory,
lets call it /authRoot where the administrators can store
customized login pages, graphics and so on.
So, by neccessity, it allows unauthenticated access to this
directory.
Unfortunately the ISS bugg allows one to "break out" of this
direcotry by appending %1u%1u (".." in other words).
So, to access default.asp we could would enter the url...
http://server/authRoot/%1u%1u/default.asp
And, ooops, unauthenticate access...
- Next message: Justin Tripp: "HPUX Aserver revisited."
- Previous message: John Archie: "Re: majordomo local exploit"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
This archive was generated by hypermail 2b27 : Sun Jan 02 2000 - 14:35:08 CST