Likes Likes:  0
Resultaten 1 tot 3 van de 3
Geen
  1. #1
    N.N.P
    Coldfusion Fusebox V4.1.0 Vulnerability
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Coldfusion Fusebox V4.1.0 Vulnerability

    This was discovered by myself over the weekend. I cant find out what
    versions of fusebox this vulnerability is in but seeing as it affects
    the main fusebox page I can only assume it is the latest v4.1.0 and
    possibly some older versions.

    According to the Fusebox site,=20

    What is Fusebox?
    Fusebox is a standard framework for building web-based applications.
    =20
    Basically the "fusebox" takes all requests for actions such as
    searching, login etc etc on a site and passes it off to the relevant
    script (check out their site for more info). Normally you see
    something like

    Basically this vulnerability allows the execution of JS. For example

    http://www.site.org/index.cfm?fuseaction=3D"><script>document.location=3D"h=
    ttp://silentcode.net"</script>

    Im sure if anyone feels like screwing around with it im sure you'll
    find some other interesting problems with it, the thing is like swiss
    cheese ; )

    Comments and critisisms are welcome.

    Comments:
    Some sites using fusebox are not vulnerable. It appears to be possible
    to set a standard page for errors and some filter out the script tags.
    Also some will work with redirects and normal alert boxes but will
    filter out document.cookie. In cases like these it often proves useful
    to leave in the actual fuseaction. This helps avoid the error in some
    cases. e.g
    http://www.site.org/index.cfm?fuseac...sebox.overview"><script>alert(=
    document.cookie)</script><

    Usage:
    The main usage of this vulnerability would be cookie stealing. This is
    achieved by redirecting the user to a php script on a site you control
    with the users cookie as a parameter to the script. Then to avoid
    raising suspicions redirect them back to the page they thought they
    were accessing. Google "cookie stealing" for more info.

    Fix:
    Filtering all input to the fusebox correctly should solve this. As
    well as that setting it to surpress errors and having a default error
    page should also help.

    Googling for allinurl:/index.cfm?fuseaction=3D will give you an idea of
    how many sites are possibly vulnerable.

    Enjoy,
    NNP

    As a side note, if the server isnt set to surpress errors you can get
    some interesting info such as full path disclosure etc by passing in
    special characters such as ?

    e.g https://site.com/index.cfm?fuseaction=3D?

    If you want to see an example of what i mean have a look on
    http://silentcode.net/community

    I've posted a vulnerable site there.
    --=20
    http://silentcode.net

  2. #2
    Ian Mitchell
    Coldfusion Fusebox V4.1.0 Vulnerability
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: Coldfusion Fusebox V4.1.0 Vulnerability


    Having been a modified fusebox developer for a while I can say that there
    are likely MANY more problems besides that, such as SQL injection and XSS
    issues that still need to be resolved in many Fusebox apps. We addressed
    them by creating a standard parse function in the index.cfm file that
    prevented any sub fuses from being affected. However since I was under
    contract I can't provide said code, sorry. But I highly advise a security
    module that does basic sanity checks, authentication validation, tests for
    session hijacks/fixations, and other funny business that gets thrown at
    the fusebox. This security module or fuse needs to be called first and
    formost before ANY other fuses get called and should be accessed directly
    from the index.cfm file before anything else happens. Coldfusion itself
    doesn't do much for sanity checks, it's up to the developer to take those
    into consideration.

    What I found interesting was that the first 10 entries returned from the
    google search were Senator's... interesting.



  3. #3
    steven@lovebug.org
    Coldfusion Fusebox V4.1.0 Vulnerability
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: Coldfusion Fusebox V4.1.0 Vulnerability


    List of people you could have contacted with regarding the bug:

    http://www.fusebox.org/index.cfm?fus...ox.teamfusebox

    Forum full of users and site staff that you could have
    contacted/questioned about the bug:

    http://www.fusebox.org/forums/



    Steven


    ----- Original Message -----
    From: "N.N.P" <version5@gmail.com>
    To: <bugtraq@securityfocus.com>
    Sent: Wednesday, August 03, 2005 4:19 AM
    Subject: Coldfusion Fusebox V4.1.0 Vulnerability


    This was discovered by myself over the weekend. I cant find out what
    versions of fusebox this vulnerability is in but seeing as it affects
    the main fusebox page I can only assume it is the latest v4.1.0 and
    possibly some older versions.

    According to the Fusebox site,

    What is Fusebox?
    Fusebox is a standard framework for building web-based applications.

    Basically the "fusebox" takes all requests for actions such as
    searching, login etc etc on a site and passes it off to the relevant
    script (check out their site for more info). Normally you see
    something like

    Basically this vulnerability allows the execution of JS. For example

    http://www.site.org/index.cfm?fuseaction="><script>document.location="http://silentcode.net"</script>

    Im sure if anyone feels like screwing around with it im sure you'll
    find some other interesting problems with it, the thing is like swiss
    cheese ; )

    Comments and critisisms are welcome.

    Comments:
    Some sites using fusebox are not vulnerable. It appears to be possible
    to set a standard page for errors and some filter out the script tags.
    Also some will work with redirects and normal alert boxes but will
    filter out document.cookie. In cases like these it often proves useful
    to leave in the actual fuseaction. This helps avoid the error in some
    cases. e.g
    http://www.site.org/index.cfm?fuseac...sebox.overview"><script>alert(document.cookie)</script><

    Usage:
    The main usage of this vulnerability would be cookie stealing. This is
    achieved by redirecting the user to a php script on a site you control
    with the users cookie as a parameter to the script. Then to avoid
    raising suspicions redirect them back to the page they thought they
    were accessing. Google "cookie stealing" for more info.

    Fix:
    Filtering all input to the fusebox correctly should solve this. As
    well as that setting it to surpress errors and having a default error
    page should also help.

    Googling for allinurl:/index.cfm?fuseaction= will give you an idea of
    how many sites are possibly vulnerable.

    Enjoy,
    NNP

    As a side note, if the server isnt set to surpress errors you can get
    some interesting info such as full path disclosure etc by passing in
    special characters such as ?

    e.g https://site.com/index.cfm?fuseaction=?

    If you want to see an example of what i mean have a look on
    http://silentcode.net/community

    I've posted a vulnerable site there.
    --
    http://silentcode.net


Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics