Likes Likes:  0
Resultaten 1 tot 3 van de 3
Geen
  1. #1
    Faz
    Lotus Domino DOT Bug Allows for Source Code Viewing
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Lotus Domino DOT Bug Allows for Source Code Viewing

    Through some testing against some Lotus Domino web servers (verified in
    version 5 & 6), if you append a period to the end of a non-default Lotus
    file type (non .NSF, .NTF, etc) via your browser URL request, you will be
    prompted to download the file. This has a possible repercussion of the
    ability to view the source code for such add-in web handlers such as Crystal
    Reports, Perl scripts and others. In some cases (such as Crystal Reports)
    where such file types are server-side run (similar to .ASP), they may
    reference additional INCLUDE files that contain logins and passwords. An
    attacker can easily use this technique to view the server-side source code
    and additional INCLUDE files to obtain private information.

    For example:
    http://some.dominoserver.com/reports/secretreport.csp. <-- End the URL with
    a <period>
    http://some.dominoserver.com/cgi-bin/myscript.pl . <-- notice the
    <space><period>
    http://some.dominoserver.com/cgi-bin/runme.exe%20. <-- combination of hex
    <space> and an ASCII period
    http://some.dominoserver.com/reports...port.csp%20%2E <-- All hex
    values
    will return the actual .CSP source code instead of the compiled report. This
    seems to work for all types of non-native Lotus Domino file types. A short
    term workaround is to create Domino redirection filters for the various
    non-native file types and ending them with the combinations above, but some
    creative formatting of the URL can easily bypass these redirection filters.

    Lotus has been notified, and during the initial report, was not too
    concerned about this. It has been passed to development for further
    consideration. Maybe getting the word out about this will apply some
    pressure to Lotus to issue a fix.


  2. #2
    Robert Mays
    Lotus Domino DOT Bug Allows for Source Code Viewing
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: Lotus Domino DOT Bug Allows for Source Code Viewing

    faz@attbi.com ("Faz") wrote in message news:<b2ejin$1sm8$1@FreeBSD.csie.NCTU.edu.tw>...
    > Through some testing against some Lotus Domino web servers (verified in
    > version 5 & 6), if you append a period to the end of a non-default Lotus
    > file type (non .NSF, .NTF, etc) via your browser URL request, you will be
    > prompted to download the file. This has a possible repercussion of the
    > ability to view the source code for such add-in web handlers such as Crystal
    > Reports, Perl scripts and others. In some cases (such as Crystal Reports)
    > where such file types are server-side run (similar to .ASP), they may
    > reference additional INCLUDE files that contain logins and passwords. An
    > attacker can easily use this technique to view the server-side source code
    > and additional INCLUDE files to obtain private information.
    >
    > For example:
    > http://some.dominoserver.com/reports/secretreport.csp. <-- End the URL with
    > a <period>
    > http://some.dominoserver.com/cgi-bin/myscript.pl . <-- notice the
    > <space><period>
    > http://some.dominoserver.com/cgi-bin/runme.exe%20. <-- combination of hex
    > <space> and an ASCII period
    > http://some.dominoserver.com/reports...port.csp%20%2E <-- All hex
    > values
    > will return the actual .CSP source code instead of the compiled report. This
    > seems to work for all types of non-native Lotus Domino file types. A short
    > term workaround is to create Domino redirection filters for the various
    > non-native file types and ending them with the combinations above, but some
    > creative formatting of the URL can easily bypass these redirection filters.
    >
    > Lotus has been notified, and during the initial report, was not too
    > concerned about this. It has been passed to development for further
    > consideration. Maybe getting the word out about this will apply some
    > pressure to Lotus to issue a fix.


    The issue that you describe is not a bug with Domino. Rather, it is
    caused by a lack of proper Domino security implementation by the
    administrator. By default, any non-Domino file type that resides
    under the Domino directory structure can be accessed and downloaded
    anonymously. However, as with other web servers, you can implement
    restrictions to specific files and/or file paths in order to prevent
    anonymous access or to restrict access to limited users. This
    function is implemented in Domino by defining one or more File
    Restrictions in the Domino diectory for the selected server.

    Your specific issue with Crystal Reports should be easily handled by
    implementing File Restrictions that only allows the server to access
    these files, since they're intended for server-side access only.
    Placing such files into specific sub-directories under the Domino HTML
    root directory is also an advised technique. This helps to minimize
    the number of File Restrictions to define, since a File Restriction
    can also be defined for an entire directory.

  3. #3
    JRedmond@ymcastlouis.org
    Lotus Domino DOT Bug Allows for Source Code Viewing
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: Lotus Domino DOT Bug Allows for Source Code Viewing


    "Faz" <faz@attbi.com> wrote:
    > Through some testing against some Lotus Domino web servers (verified in

    version 5 & 6), if you append a period to the end of a non-default Lotus
    file type (non .NSF, .NTF, etc) via your browser URL request, you will be
    prompted to download the file.

    I have been unable to recreate this on Domino 5.0.11, running on OS/400
    V5R1. I get a 404 instead, whether I use MSIE or Mozilla or Opera, whether
    the trailing dot is present or not, and whether my connection is anonymous
    or name-and-password authenticated.

    The difference here probably lies in the "Does this server use IIS?" option
    on the Domino Server Document (as maintained by the server's
    administrator). If checked, IIS handles all HTTP requests first. If this
    option is enabled, and the request is for non-Domino traffic (such as the
    examples listed in the original message), Domino does not receive the
    request. I have this option disabled on the system I tested; that
    particular operating system is not blessed with IIS.

    Please check Microsoft's knowledge base and this list's archives to see if
    this is another IIS bug. If that's the case, then it may be why Lotus is
    "not too concerned about this" - it's nothing they can fix.

    ************************************
    James Redmond, Domino Administrator
    YMCA of Greater St. Louis
    +1-314-436-1177 ext. 326
    FAX +1-314-436-1901
    jredmond@ymcastlouis.org
    ************************************



Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics