Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Multiple vulnerabilities in SAP WebAS 6.40 and 7.00 (technical details) |
|---|---|
| Date: | Thu, 08 Feb 2007 23:08:53 +0100 |
Multiple vulnerabilities in SAP Web Application Server
Technical details
Application : SAP Web AS 6.40 < patch 136 and 7.00 < patch 66
Platform : All platforms (except the third vulnerability)
Impacts : Remote file disclosure, remote DoS, local privilege escalation
Release Date : 8 February 2007
Author : Nicob <nicob at nicob.net>
Vulnerabilities technical details :
===================================
1) A remote file disclosure vulnerability allows reading any file to
which the user that the SAP Web Application Server is running as had
access. Under Windows, the service runs by default under the
SAPServiceJ2E account. This account is member of the local administrator
group.
Exploit : use "r3-stealer-1.0.pl" (attached)
Note : Absolute paths can be used, so "C:\boot.ini" and "\\10.11.12.13
\share\image.jpg" are both OK.
2) A remote denial of service allows crashing the enserver.exe process.
Exploit : send "\x72\xfe" on port UDP/64999
3) A local privilege escalation vulnerability allows any local user to
use the file disclosure vulnerability to access an user-controlled
process via a named pipe and impersonate as user SAPServiceJ2E. The
exploitation is possible only on Windows 2000 pre-SP4, Windows XP
pre-SP2 and Windows NT.
Exploit : use "r3-stealer-1.0.pl" (attached) and "tac0tac0.c" [1]
Solutions :
===========
Apply patch 136 or newer for version 6.40
Apply patch 66 or newer for version 7.00
Note : the mentioned patch level refers to the enqueue server
More details can be found in SAP notes 948457 and 959877
[1] : http://security.nnov.ru/files/tac0tac0.c
Nicob
r3-stealer-1.0.pl
Description: Perl program
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Full-disclosure] iDefense Security Advisory 02.07.07: Trend Micro AntiVirus UPX Parsing Kernel Buffer Overflow Vulnerability, iDefense Labs |
|---|---|
| Next by Date: | TFTP directory traversal in Kiwi CatTools, Nicob |
| Previous by Thread: | [Full-disclosure] iDefense Security Advisory 02.07.07: Trend Micro AntiVirus UPX Parsing Kernel Buffer Overflow Vulnerability, iDefense Labs |
| Next by Thread: | TFTP directory traversal in Kiwi CatTools, Nicob |
| Indexes: | [Date] [Thread] [Top] [All Lists] |