New User, Welcome!     Login

Ragnarok Online Control Panel Authentication Bypass Vulnerability [new method]

From: dp14 hotmail com
To: bugtraq securityfocus com
Cc:
Subject: Ragnarok Online Control Panel Authentication Bypass Vulnerability [new method]
Date: Fri - Aug 31, 2007 05:51 AM


VaLiuS has reported a vulnerability in Ragnarok Online Control Panel,
which can be exploited by malicious people to bypass certain security
restrictions.

The vulnerability is caused due to an error in the authentication
process when checking page access. This can be exploited to bypass
the authentication process via a specially crafted URL with an
appended non-restricted page.

The /.../ reffers to directory crawling

Example:
http://www.example.com/CP/...../account_manage.php/login.php

Successful exploitation requires that files are served from an Apache
HTTP server.

The vulnerability has been reported in version 4.3.4a. Other versions
may also be affected.

SOLUTION:
Edit the source code to ensure that the authentication process is
properly performed.

PROVIDED AND/OR DISCOVERED BY:
Calypso Steweren




Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!