Re: def-2001-32 - Allaire JRun directory browsing vulnerability

From: null null (sl2shoat_private)
Date: Thu Nov 29 2001 - 13:26:50 PST

  • Next message: secureat_private: "[CLA-2001:443] Conectiva Linux Security Announcement - wu-ftpd"

    
     ('binary' encoding is not supported, stored as-is)
    In-Reply-To: <PKEMKDGKMFGJMOHGPHFPAEBJCAAA.george.hedforsat_private>
    
    Here are some HTTP header dumps from different 
    web servers that are vulnerable to the \%3f.jsp 
    directory content vulnerability
    
    HTTP/1.0 200 OK
    Date: Fri, 30 Nov 2001 03:43:27 GMT
    Server: Jetty/3.1.RC8 (Linux 2.2.16-22enterprise x86)
    Servlet-Engine: Jetty/3.1 (JSP 1.1; Servlet 2.2; java 
    1.3.0)
    
    
    HTTP/1.1 200 OK
    Date: Fri, 30 Nov 2001 04:00:20 GMT
    Server: Apache/1.3.20 (Linux/SuSE) mod_jk
    Last-Modified: Thu, 01 Nov 2001 21:20:47 GMT
    
    HTTP/1.1 302 Found
    Date: Fri, 30 Nov 2001 04:03:07 GMT
    Server: Apache/1.3.14 (Unix) PHP/4.0.6 
    ApacheJServ/1.1.2
    Servlet-Engine: Tomcat Web Server/3.2.3 (JSP 1.1; 
    Servlet 2.2; Java 1.
     5.8 sparc; java.vendor=Sun Microsystems Inc.)
    
    mad love to securityfocus.com....
    
    -slow2show-
    University of Florida
    
    >Received: (qmail 16045 invoked from network); 29 
    Nov 2001 23:59:04 -0000
    >Received: from outgoing3.securityfocus.com 
    (HELO outgoing.securityfocus.com) (66.38.151.27)
    >  by mail.securityfocus.com with SMTP; 29 Nov 
    2001 23:59:04 -0000
    >Received: from lists.securityfocus.com 
    (lists.securityfocus.com [66.38.151.19])
    >	by outgoing.securityfocus.com (Postfix) 
    with QMQP
    >	id 8AADDA3397; Thu, 29 Nov 2001 
    11:10:59 -0700 (MST)
    >Mailing-List: contact bugtraq-
    helpat_private; run by ezmlm
    >Precedence: bulk
    >List-Id: <bugtraq.list-id.securityfocus.com>
    >List-Post: <mailto:bugtraqat_private>
    >List-Help: <mailto:bugtraq-
    helpat_private>
    >List-Unsubscribe: <mailto:bugtraq-
    unsubscribeat_private>
    >List-Subscribe: <mailto:bugtraq-
    subscribeat_private>
    >Delivered-To: mailing list 
    bugtraqat_private
    >Delivered-To: moderator for 
    bugtraqat_private
    >Received: (qmail 18871 invoked from network); 29 
    Nov 2001 11:03:11 -0000
    >From: "George Hedfors" 
    <george.hedforsat_private>
    >To: "Felix Huber" <huberfelixat_private>,
    >	"BugTraq" <bugtraqat_private>
    >Subject: RE: def-2001-32 - Allaire JRun directory 
    browsing vulnerability
    >Date: Thu, 29 Nov 2001 12:03:57 +0100
    >Message-ID: 
    <PKEMKDGKMFGJMOHGPHFPAEBJCAAA.george.h
    edforsat_private>
    >MIME-Version: 1.0
    >Content-Type: text/plain;
    >	charset="iso-8859-1"
    >Content-Transfer-Encoding: 7bit
    >X-Priority: 3 (Normal)
    >X-MSMail-Priority: Normal
    >X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 
    (9.0.2910.0)
    >X-MimeOLE: Produced By Microsoft MimeOLE 
    V5.50.4807.1700
    >Importance: Normal
    >In-Reply-To: <020401c178c4$3b322630
    $0205a8c0@athlon>
    >
    >That Apache must be running some JRun engine, 
    could you find out wich?
    >
    >Regards, George
    >
    >-----Original Message-----
    >From: Felix Huber [mailto:huberfelixat_private]
    >Sent: den 29 november 2001 11:55
    >To: George Hedfors; bugtraqat_private
    >Subject: Re: def-2001-32 - Allaire JRun directory 
    browsing vulnerability
    >
    >
    >> ------------------------=[Affected Systems]=-------------
    -------------
    >> Under Windows NT/2000(any service pack) and 
    IIS 4.0/5.0:
    >> - JRun 3.0 (all editions)
    >> - JRun 3.1 (all editions)
    >> ----------------------=[Detailed Description]=------------
    ------------
    >> Upon sending a specially formed request to the 
    web server, containing
    >> a '.jsp' extension makes the JRun handle the 
    request. Example:
    >>
    >> http://www.victim.com/%3f.jsp
    >
    >Not only IIS is affected, i found a vulnerable Site 
    running Apache 1.3.19 on
    >Solaris.
    >
    >A NASL Script is attached to find affected systems.
    >
    >
    >MfG
    >Felix Huber
    >
    >
    >-------------------------------------------------------
    >Felix Huber, Security Consultant, Webtopia
    >Guendlinger Str.2, 79241 Ihringen - Germany
    >huberfelixat_private     (07668)  951 156 (phone)
    >http://www.webtopia.de     (07668)  951 157 (fax)
    >                                         (01792)  205 724 (mobile)
    >-------------------------------------------------------
    >
    >
    >
    >
    >
    



    This archive was generated by hypermail 2b30 : Fri Nov 30 2001 - 14:13:49 PST