|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
From: snsadv
lac.co.jpDate: Tue Aug 21 2001 - 17:35:51 CDT
----------------------------------------------------------------------
SNS Advisory No.39
WinWrapper Professional 2.0 Remote Arbitrary File Disclosure
Vulnerability
Problem first discovered: Mon, 16 Jul 2001
Published: Mon, 20 Aug 2001
----------------------------------------------------------------------
Overview:
---------
WinWrapper Professional 2.0 is a firewall software. It provides Web-based
remote console. This console contains a vulnerability to allow
attacker to read arbitrary files.
Problem Description:
--------------------
WinWrapper Professional 2.0 is a firewall software which is developed
by ASCII NT, INC. It is designed to protect WindowsNT/2000 systems,
and provides additional Web-based capability of remote administration.
But the program which is used as remote administration server contains
a vulnerability. It is possible to read arbitrary files on the target
system with Local System context.
Ex.
note:
Tested Version:
Tested OS:
Patch Information:
http://www.tsc.ant.co.jp/products/download.htm
Discovered by:
http://
4096 is the port number used by default.
---------------
WinWrapper Professional 2.0 Ver.2.0.0
----------
Windows 2000 Server + SP2 [Japanese]
------------------
Fixed module (Ver.2.0.1) is available on following URL:
--------------
ARAI Yuu (LAC / y.arai
lac.co.jp
Disclaimer:
-----------
All information in these advisories are subject to change without any
advanced notices neither mutual consensus, and each of them is released
as it is. LAC Co.,Ltd. is not responsible for any risks of occurrences
caused by applying those information.
References
----------
Archive of this advisory(in preparation now):
http://www.lac.co.jp/security/english/snsadv_e/39_e.html
------------------------------------------------------------------
Secure Net Service(SNS) Security Advisory <snsadv
lac.co.jp>
Computer Security Laboratory, LAC http://www.lac.co.jp/security/
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]