[SecurityOffice] BadBlue Web Server v1.7 Protected File Access Vulnerability

From: Tamer Sahin (tsat_private)
Date: Thu Oct 24 2002 - 11:46:06 PDT

  • Next message: Toni Lassila: "IBM Infoprint Remote Management Simple DoS"

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: MD5
    
    - --[ BadBlue Web Server v1.7 Protected File Access Vulnerability ]--
    
    - --[ Type
    
    File Disclosure
    
    - --[ Release Date
    
    October 24, 2002
    
    - --[ Product / Vendor
    
    BadBlue is a very small footprint, Win32 web server that supports a suprisingly large
    array of features: NT-based security; application-serving via ISAPI, CGI, PHP, Perl etc.;
    CLF logging; virtual directories; directory browsing; service installation; etc.
    
    http://www.badblue.com
    
    - --[ Summary
    
    It is possible to construct a web request which is capable of accessing the contents
    of password protected files/folders on the BadBlue Web Server v1.7. This vulnerability
    may only be exploited to access password-protected files in sub-folders of wwwroot.
    
    http://host//secret/
    
    - --[ Tested
    
    Windows 2000 Sp3 / BadBlue Web Server v1.7
    Windows 98 SE / BadBlue Web Server v1.7
    
    - --[ Vulnerable
    
    BadBlue Web Server v1.7
    
    - --[ Disclaimer
    
    http://www.securityoffice.net is not responsible for the misuse or illegal use of any
    of the information and/or the software listed on this security advisory.
    
    - --[ Author
    
    Tamer Sahin
    tsat_private
    http://www.securityoffice.net
    
    All our advisories can be viewed at http://www.securityoffice.net/articles/
    
    Please send suggestions, updates, and comments to feedbackat_private
    
    (c) 2002 SecurityOffice
    
    This Security Advisory may be reproduced and distributed, provided that this Security
    Advisory is not modified in any way and is attributed to SecurityOffice and provided
    that such reproduction and distribution is performed for non-commercial purposes.
    
    Tamer Sahin
    http://www.securityoffice.net
    
    -----BEGIN PGP SIGNATURE-----
    Version: 2.6
    
    iQEVAwUAPbg/7/pL5ibJRTtBAQGRFggAgW7l+T5GHxy59Y5YudqU+MJs8FF8JAcr
    qTtyUewhF7IB3NtvW6BVEMfzh5Yyd5yJGsHY8eHCYlIsS994ltfyY+isvx96BPdH
    iCQfhgP4SgiHP7AG6Rqf66WsosM7LrihMYZJRspuSmVy+341e439nrXcj/xF8Nbm
    nUSBvlhtrNavc8TrlXErMz3veL0ql6lB9lt94PycALksFl2HB+9v2PwVopulfCUw
    wpUrwCQ91wP/1+ewbbvp5rlEnasoSIJTMEF/5H8DGgJvA5VPE3DqH8Pz4FtlHAGZ
    StprMg28Wr+cAc6IZWFaV+PGZ8pl1HjIQotGbLWfPGRuAJguHvt+sg==
    =CpEM
    -----END PGP SIGNATURE-----
    



    This archive was generated by hypermail 2b30 : Fri Oct 25 2002 - 01:20:11 PDT