RE: def-2001-32 - Allaire JRun directory browsing vulnerability

From: George Hedfors (george.hedforsat_private)
Date: Thu Nov 29 2001 - 03:03:57 PST

  • Next message: David Lodge: "Re: Audiogalaxy again"

    That Apache must be running some JRun engine, could you find out wich?
    
    Regards, George
    
    -----Original Message-----
    From: Felix Huber [mailto:huberfelixat_private]
    Sent: den 29 november 2001 11:55
    To: George Hedfors; bugtraqat_private
    Subject: Re: def-2001-32 - Allaire JRun directory browsing vulnerability
    
    
    > ------------------------=[Affected Systems]=--------------------------
    > Under Windows NT/2000(any service pack) and IIS 4.0/5.0:
    > - JRun 3.0 (all editions)
    > - JRun 3.1 (all editions)
    > ----------------------=[Detailed Description]=------------------------
    > Upon sending a specially formed request to the web server, containing
    > a '.jsp' extension makes the JRun handle the request. Example:
    >
    > http://www.victim.com/%3f.jsp
    
    Not only IIS is affected, i found a vulnerable Site running Apache 1.3.19 on
    Solaris.
    
    A NASL Script is attached to find affected systems.
    
    
    MfG
    Felix Huber
    
    
    -------------------------------------------------------
    Felix Huber, Security Consultant, Webtopia
    Guendlinger Str.2, 79241 Ihringen - Germany
    huberfelixat_private     (07668)  951 156 (phone)
    http://www.webtopia.de     (07668)  951 157 (fax)
                                             (01792)  205 724 (mobile)
    -------------------------------------------------------
    



    This archive was generated by hypermail 2b30 : Thu Nov 29 2001 - 17:50:13 PST