RE: Outlook Web Access authentication bypass

From: Chris Robertson (Chris.Robertsonat_private)
Date: Fri May 23 2003 - 10:17:54 PDT

  • Next message: Julien Lanthea: "Re: Options Parsing Tool library buffer overflows."

    Please disregard this.  A configuration change had been unknowingly made on
    the Exchange server (making the test account an Exchange Admin).
    
    I sincerly apologize for any confusion this may have caused.
    
    Chris Robertson
    
    -----Original Message-----
    From: Chris Robertson [mailto:Chris.Robertsonat_private]
    Sent: Friday, May 23, 2003 1:03 AM
    To: 'bugtraqat_private'
    Subject: Outlook Web Access authentication bypass
    
    
    This exploit exhibits the same symptoms as CAN-2002-0507 however I have
    found it is possible on an Exchange 5.5 (patches current to within ~3
    months) single system Outlook Web Access install (IIS and 
    Exchange on the
    same server) to access any mailbox once the client has been successfully
    authenticated in Netscape 7.0 on Windows 2k and Redhat 7.2, 
    Mozilla 1.0.1,
    Galeon 1.2.5, and Konqueror 3.0.3-13 on Redhat 8.0.  
    Additionally under IE
    5.50.4807.2300 it is possible to get the same behavior by canceling an
    attempted login to a non-authorized mailbox and editing the url from
    ..."isnewwindow=0"... to ..."isnewwindow=1"...
    
    Does anyone have anymore info on this?
    
    Thanks,
    Chris Robertson
    Security Engineer
    Instill Corp.
    



    This archive was generated by hypermail 2b30 : Fri May 23 2003 - 11:41:10 PDT