Likes Likes:  0
Resultaten 1 tot 3 van de 3
Geen
  1. #1
    Barry Zubel
    RE: axis2400 webcams
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    RE: axis2400 webcams

    Tested the viewing of http://server/log/messages on Axis 2100 model, and =
    it is
    vulnerable.

    Didn't try to check the overwrite vulnerability - I'd rather not, just =
    in case.


    Barry Zubel
    Able Packaging Designs Ltd

    ************************************************** ***********************=
    **
    This email may contain confidential information and/or copyright =
    material.
    This email is intended for the use of the addressee only. Any =
    unauthorised
    use may be unlawful. If you receive this email by mistake, please advise
    the sender immediately by using the reply facility in your email =
    software.
    Thank you for your cooperation.

    Please note that any opinions expressed in this e-mail are those of the
    author personally and are not necessarily those of the Company or any of
    its subsidiary companies, none of whom accept responsibility for the
    contents of the message. This footnote also confirms that this email
    message has been swept for the presence of computer viruses.
    ************************************************** ***********************=
    **



    -----Original Message-----
    From: Martin Eiszner [mailto:martin@websec.org]=20
    Sent: 28 February 2003 09:46
    To: bugtraq@securityfocus.com
    Subject: axis2400 webcams




    2002@WebSec.org/Martin Eiszner

    =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3 D=3D=3D=3D=3D=3D=3D=3D=3D=
    =3D=3D=3D=3D=3D=3D=3D=3D=3D
    Security REPORT axis webcam 2400.? =
    =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3 D=3D=3D=3D=3D=3D=3D=3D=3D=
    =3D=3D=3D=3D=3D=3D=3D=3D=3D

    this document: http://www.websec.org/adv/axis2400.txt.html

    Product: Axis Webserver for 2400 ??
    Vulnerablities: denial of service, information disclosure, non-confirmed =
    script
    execution
    Vendor: Axis (http://www.axis.com)
    Vendor-Status: E-Mail to "security@axis.com" and "anne.rhenman@axis.com" =
    date:
    17.01.2003
    Vendor-Patch: no response (28.02.2003)

    Local: NO
    Remote: YES

    =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
    Introduction
    =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D

    webcam system including modified boa-webserver and web-based =
    admin-interface ...


    =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3 D=3D=3D=3D=3D
    Vulnerability Details
    =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3 D=3D=3D=3D=3D


    1) INFORMATION DISCLOSURE

    http-requests to:

    ---*---
    http://server/support/messages
    ---*---

    responds with /var/log/messages.
    it is not password protected and might disclose sensitive information.


    2) DOS / OVERWRITING SYSTEM-FILES
    requesting:
    ---*---
    http://server/axis-cgi/buffer/command.cgi?
    buffername=3DX&
    prealarm=3D1&
    postalarm=3D1&
    do=3Dstart&
    uri=3D/jpg/quad.jpg&
    format=3D[bad input]
    ---*---

    allows an attacker to overwrite important files on the system (all fifos =
    for
    example) leading to an effective DOS-attack.


    3) ARBITRARY FILE CREATION

    a request like:
    ---*---
    /axis-cgi/buffer/command.cgi?whatever params buffername=3D[relative path =
    to
    directory] format=3D[relative path to arbitrary file name]
    ---*---

    will create [relative path to arbitrary file name] or [relative path to =
    a.
    directory]

    if somebody is able to change content of error messages he might be able =
    to
    create and execute arbitrary script-files(php fE.).


    severity: LOW-MEDIUM


    =3D=3D=3D=3D=3D=3D=3D
    Remarks
    =3D=3D=3D=3D=3D=3D=3D

    ---

    =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3 D=3D=3D=3D
    Recommended Hotfixes
    =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3 D=3D=3D=3D

    software patch.


    EOF Martin Eiszner / @2002WebSec.org
    =3D=3D=3D=3D=3D=3D=3D
    Contact
    =3D=3D=3D=3D=3D=3D=3D

    WebSec.org / Martin Eiszner
    Gurkgasse 49/Top14
    1140 Vienna

    Austria / EUROPE

    mei@websec.org
    http://www.websec.org








  2. #2
    Sergio Gelato
    RE: axis2400 webcams
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: axis2400 webcams

    * Barry Zubel [2003-02-28 17:19:04 -0000]:
    > Tested the viewing of http://server/log/messages on Axis 2100 model, and it is
    > vulnerable.


    Sorry, can't reproduce it on a 2100 with firmware 2.33.1. It prompts me
    for authentication, and *only* the root username/password pair grant me
    access to /support/messages (not /log/messages as you wrote). Other
    less privileged username/password pairs (yes, I've enabled those) return
    a "password is incorrect" error.

    If you don't password-protect the root account you get of course what
    you deserve. And if you claim a product is vulnerable without specifying
    which software (here firmware) revision(s) you've tested, you don't
    sound terribly convincing.

    [Side note:
    For some strange reason the 2.33.1 "service release" of the firmware is
    not advertised on the www.axis.com firmware download pages; you may
    however find it by anonymous ftp in the sr/ subdirectory. See the
    message from product-security@axis.com to BugTraq on 2002-12-20.]

  3. #3
    jean-philippe Gaulier
    RE: axis2400 webcams
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: axis2400 webcams


    Product tested : AXIS 2401 release 2.32


    > http://server/support/messages
    > responds with /var/log/messages.


    That's fine

    > 2) DOS / OVERWRITING SYSTEM-FILES
    > 3) ARBITRARY FILE CREATION


    Don't work. Ask for a login/pass.


    Best regards,
    Jean-Philippe Gaulier

    ----------------------
    Administrateur MAN -- Syst=E8mes et R=E9seaux
    Universit=E9 de Limoges

Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics