OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: acz [iSecureLabs] (aurelien.cabezoniSecureLabs.com)
Date: Wed Aug 22 2001 - 09:28:49 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    -- [ iSecureLabs BadBlue v1.02 beta for Windows 98, ME and 2000
    Advisory ] --

    BadBlue v1.02 beta for Windows 98, ME and 2000 .php Source Code Disclosure
    Vulnerability
    Problem discovered: 22/08/2001

    -- [ Overview ] --

    BadBlue is a tiny, free download that lets you share files, search other
    PCs and even run powerful web applications.
    Badblue support .php extension.
    It is possible to retrieve full .php source code.

    -- [ Description ] --

    Badblue contains an input validation vulnerability which may lead to
    download the full source code of .php pages.
    This is due to a lack of checks for NULL bytes.

    Exemple:
    http://myBadBlue.com/test.php%00

    Note: It is possible too to download .dll file used by BadBlue.

    Exmeple:
    http://myBadBlue.com/ext.dll%00

    -- [ Tested Version ] --

    BadBlue v1.02 beta for Windows 98, ME and 2000

    -- [ Fix ] --

    According to BadBlue team, a fix will be included in the 1.5 version due
    within the next week.
    http://badblue.com

    -- [ Discovered by ] --

    Cabezon Aurélien | aurelien.cabezoniSecureLabs.com
    http://www.iSecureLabs.com | French Security portal