Likes Likes:  0
Resultaten 1 tot 2 van de 2
Geen
  1. #1
    Rushjo@tripbit.org
    Re: TA-2003-06 Directory Transversal Vulnerability in iWeb Server
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: TA-2003-06 Directory Transversal Vulnerability in iWeb Server

    Hi akcess,


    thx for your feedback. But not all of your comments are right.
    First I wrote this in the advisory:

    [qoute]
    The vendor has reportedly been notified. But the vendor told us that is
    an old bug. We don't think so.
    [/ qoute]

    Alright perhaps next time it will be better to mention the url of the
    old bug. And of course it is an "another form of the old bug" but did
    you really read the old advisory? For example the recommended solution?

    [quote]
    * taken from http://securityfocus.com/archive/1/318775 *

    ......:[ Vendor Status :

    14/04/03 Initial Contact Made
    15/04/03 Vendor Responded
    15/04/03 Vendor Released Updated Version

    ......:[ Solution :

    Remove old iWeb application and download and install the updated
    version which can be found at:

    http://ashleybrown.co.uk/downloads/iws2.exe
    [/qoute]

    And this is the point. We tested the "safe" iWeb Server2 and still found
    this bug. So we don't think that it is fixed. Because of the reaction of
    the vendor we deceided to post this here.

    And of course thanks for hints to posidron's "work". He "rebuilded" this
    tool with the help of your hints.


    Have a lot of fun

    Rushjo



  2. #2
    Steven M. Christey
    Re: TA-2003-06 Directory Transversal Vulnerability in iWeb Server
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: TA-2003-06 Directory Transversal Vulnerability in iWeb Server


    There are so many variants to directory traversal vulnerabilities,
    especially in web servers and other software where encoding and
    canonicalization is such a factor, that I have seen a number of
    confusing cases such as this.

    It definitely helps when the researcher who discovers a new variant
    specifically references the old variant and says how the underlying
    problem is different. This doesn't seem to happen too frequently,
    though, and distinguishing between variants gets much more difficult
    when it is not known if the vendor has fixed the original variant.

    In this case, it looks like the programmer introduced what I call a
    "validate-before-canonicalize" error, for lack of a better term: the
    software may well strip ".." sequences from the input (the original
    bug), but the programmer does this cleansing *before* the operation
    that does the URL decoding (kind of like a new bug - performing
    operations in the wrong order).

    As programmers have slowly gotten better about avoiding the obvious
    directory traversal issues, these "validate-before-canonicalize"
    errors seem to be cropping up more frequently.


    - Steve

Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics