OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Matthew Murphy (mattmurphy_at_kc.rr.com)
Date: Sun Nov 24 2002 - 12:36:33 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    BadBlue is a P2P/Web server offered for Microsoft Windows operating systems
    by Working Resources. It has a bad security record -- file disclosure,
    remote administration, denials of service, buffer overflows, directory
    traversals, and more cross-site scripting flaws than I care to count. We
    can add information disclosure to that list, and add a new XSS hole to the
    count.

    * soinfo.php - Massive Information Leak

    If running with PHP enabled, the BadBlue server's default soinfo.php script
    can be made to cough up substantial amounts of information, including ODBC
    passwords:

    -- soinfo.php --
    <?php
        phpinfo();
    ?>
    -- soinfo.php --

    Yielding this data to an attacker, in combination with access to the
    database allows for a compromise of the database.

    * Cross-Site Scripting in ext.dll Search Page -- Again

    I've discovered another flaw in BadBlue's search engine allowing for
    cross-site scripting:

    ');alert(document.cookie);//
    ')" style="left:expression(eval('alert(document.cookie)'))">

    Either of these two queries will execute the alert(document.cookie) command.
    You get the idea. :-)