OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
RE: Share Point?

From: Matt Andreko (mandrekoori.net)
Date: Fri May 09 2003 - 10:25:25 CDT


Be sure to make a note that Sharepoint (at least sharepoint team
services) uses local users. It does not use some authentication
database or anything. If you tell it to create a new user for the site,
or if the site allows a user to sign up, that user has an NT password on
the system. This could help in establishing a privilege escalation
exploit.

Normally the local users are pretty stripped down, but it could be used
with an exploit of some sort that requires little privilege.

-----Original Message-----
From: Derek Schaible [mailto:dschaiblecssiinc.com]
Sent: Friday, May 09, 2003 8:33 AM
To: focus-mssecurityfocus.com
Subject: Share Point?

Greetings List,

I have a customer who wants to place sharepoint in a DMZ for outside
clients to access documents. It is their intent to place all of their
data regarding a project on the SharePoint server and use that as the
single point of storage for this project. Meaning, everyone on the team
uses this one share in the DMZ.

Does this sound safe? Has anyone here tested Share Point's security?
I'm sure this isn't the first time someone has needed to do something
like this, how have some of you handled this scenario?

I appreciate anyone's input on this matter and any advice at all is
welcome!

Thanks,
Derek

------------------------------------------------------------------------
-----
FastTrain has your solution for a great CISSP Boot Camp. The industry`s
most
recognized corporate security certification track, provides a
comprehensive
prospectus based upon the core principle concepts of security. This ALL
INCLUSIVE curriculum utilizes lectures, case studies and true hands-on
utilization
of pertinent security tools. For a limited time you can enter for a
chance
to win one of the latest technological innovations, the SEGWAY HT.
Log onto http://www.securityfocus.com/FastTrain-focus-ms
------------------------------------------------------------------------
------

-----------------------------------------------------------------------------
FastTrain has your solution for a great CISSP Boot Camp. The industry`s most
recognized corporate security certification track, provides a comprehensive
prospectus based upon the core principle concepts of security. This ALL INCLUSIVE curriculum utilizes lectures, case studies and true hands-on utilization
of pertinent security tools. For a limited time you can enter for a chance
to win one of the latest technological innovations, the SEGWAY HT.
Log onto http://www.securityfocus.com/FastTrain-focus-ms
------------------------------------------------------------------------------