Likes Likes:  0
Resultaten 1 tot 2 van de 2
Geen
  1. #1
    Michael Hendrickx
    BEA WebLogic internal hostname disclosure
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    BEA WebLogic internal hostname disclosure

    Hi,

    During a penentration test, I discovered that the BEA Weblogic Server
    reveals it hostname (on windows machines NetBIOS name) while sending the
    following request:

    GET . HTTP/1.0\r\n\r\n

    On older systems (Weblogic 7.0), a simple "BLAH . BLAH\r\n\r\n" will do
    the same trick. BEA was contacted about two weeks ago, but I haven't
    heard from them (yet).

    Regards,
    Michael

    --
    Michael Hendrickx
    Security Engineer
    Scanit NV/SA
    http://www.scanit.be


  2. #2
    Kurt Seifried
    BEA WebLogic internal hostname disclosure
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: BEA WebLogic internal hostname disclosure

    > Hi,
    >
    > During a penentration test, I discovered that the BEA Weblogic Server
    > reveals it hostname (on windows machines NetBIOS name) while sending the
    > following request:
    >
    > GET . HTTP/1.0\r\n\r\n
    >
    > On older systems (Weblogic 7.0), a simple "BLAH . BLAH\r\n\r\n" will do
    > the same trick. BEA was contacted about two weeks ago, but I haven't
    > heard from them (yet).
    >
    > Regards,
    > Michael


    Reveals hostname:
    ../
    ..//
    ..//////////////
    ..%20
    ..%20%20
    ...

    Does not reveal hostname:
    ....
    ..a
    ..1
    ..\
    ..%21

    Seems that a single "." or a "." followed by a "special" character such as
    "/" or %20 (space) works. Don't know what other "special" characters work.


    Kurt Seifried, kurt@seifried.org
    A15B BEE5 B391 B9AD B0EF
    AEB0 AD63 0B4E AD56 E574
    http://seifried.org/security/


Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics