OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: System1 (SystemTIEMIDDLEEAST.COM)
Date: Tue Jan 30 2001 - 03:44:48 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    hi,
    MS01-004 is out.

    I sent few days ago this letter to microsoft:

    -----Original Message-----
    From: Moran [mailto:MoranTIEMIDDLEEAST.com]
    Sent: Saturday, January 20, 2001 4:55 PM
    To: securemicrosoft.com
    Subject: .htr bug still exist after applying MS patches.

    Hi,
    I have server running win2000 adv. server with IIS 5.

    I have applied all relevant MS patches.

    after I did it I checked for security problems and did as follow:

    https://mysite/checkuser.asp <https://mysite/checkuser.asp>

    (the asp making a check with the SQL server for user name and password
    and i get error of unknown login ID. thats fine.)

    BUT when I did:
    https://mysite/checkuser.asp%3F+.htr
    <https://mysite/checkuser.asp%3F+.htr>

    I get blank page and when I view the source I get this line:

    <!--#include file="Conn.asp"-->

    so attacker now can know in which file my DSN details are located.

    what im worried about is that attacker can imporve this method to show
    the full asp file source.

    notice that I added all MS patches and I can still do it.

    is there any specific patch to prevent this ?

    please let me know ASAP.

    thanks,

    Moran Zavdi
    Systems Administrator
    TIE Middle East Ltd.
    Phone: (972)-9-9501113
    mailto:morantiemiddleeast.com <mailto:morantiemiddleeast.com>