New User, Welcome!     Login

Next Page >>

Log In

Memory corruption in Postfix SMTP server Cyrus SASL support (CVE-2011-1720)

Summary
=======

The Postfix SMTP server has a memory corruption error when the Cyrus
SASL library is used with authentication mechanisms other than PLAIN
and LOGIN (the ANONYMOUS mechanism is unaffected but should not be
enabled for different reasons). See below for instructions to
determine what systems are affected.

Examples of affected Cyrus SASL authentication methods are CRAM-MD5,
DIGEST-MD5, EXTERNAL, GSSAPI, KERBEROS_V4, NTLM, OTP, PASSDSS-3DES-1,

FreeWebshop.org: multiple vulnerabilities

IP spoofing
------------------------------------------------------------------------
When a user logs into FWS, the user's IP address is stored in the
database. This is done to prevent replay of (stolen) session cookies. If
FWS is called with a session cookie from a different IP address, the
user will not be logged into FWS. The IP address is obtained using
GetUserIP(). This function first checks whether the HTTP request
contains the X-Forwarded-For or Client-IP HTTP headers. These headers
are normally set by proxy servers to expose the user's real IP
address to the webservers. If these headers are found, FWS will uses the
value of the header as the user's IP address. If these headers are

Simple PHP Blog (sphpblog) <= 0.5.1 Multiple Vulnerabilities

  X-Forwarded-For: 127.0.0.1\r\n
  Connection: keep-alive\r\n\r\n
  
  Later, we'll see how to gain the administrator's session
  id. Even if we got the good session id, there is a
  protection that "normally" don't permit to be logged in.
  Let's see a part of the file "scripts/sb_login.php":
  
  28| // Check if user is logged in.
  29| if ( isset( $_SESSION[ 'logged_in' ] ) &&
    |             $_SESSION[ 'logged_in' ] == 'yes' ) {

Free Monthly Websites v2.0 - Multiple Web Vulnerabilities

24      fclose($handle);
25      $argument_arr=explode("#_1_#",$contents);
26
27      if($argument_arr[0]==$_REQUEST[username] && $argument_arr[1]==$_REQUEST[pass])
28      {
29              $_SESSION[logged_in]=true;
30              header("location:welcome.php");

Based at line 16 we know that Admin Username and Password store in admin_settings.txt NOT on Database! 
So When we login into Admin Panel, file_io.php will Read Valid Username and Password from admin_settings.txt
If you do a direct access to the file admin_settings.txt, The results is 

0day full - Free Monthly Websites v2.0 - Multiple Web Vulnerabilities

24      fclose($handle);
25      $argument_arr=explode("#_1_#",$contents);
26
27      if($argument_arr[0]==$_REQUEST[username] && $argument_arr[1]==$_REQUEST[pass])
28      {
29              $_SESSION[logged_in]=true;
30              header("location:welcome.php");

Based at line 16 we know that Admin Username and Password store in admin_settings.txt NOT on Database! 
So When we login into Admin Panel, file_io.php will Read Valid Username and Password from admin_settings.txt
If you do a direct access to the file admin_settings.txt, The results is 

[DSECRG-09-062] Alteon OS BBI (Nortell) - Multiple Vulnerabilities

2)  Stored XSS 

An attacker may inject 36 bytes of JavaScript code into log via SSH login
parameter.   Login parameter will be written into log as is. BBI or telnet login parameter
does not write  into log - only SSH. And when log page will be generated all input
from SSH login parameter will be displayed as is. 

Both vulnerabilities give chance to change switch configuration file or attack Administrator's 

glFusion <= 1.1.2 COM_applyFilter()/cookies remote blind sql injection exploit

    // Check user status
     
    $status = SEC_checkUserStatus($userid);
    if (($status == USER_ACCOUNT_ACTIVE) ||
    ($status == USER_ACCOUNT_AWAITING_ACTIVATION)) {
    $user_logged_in = 1;
     
    SESS_updateSessionTime($sessid, $_CONF['cookie_ip']);
     
    ...
     

Plesk 8.6.0 authentication flaw allows to gain virtual user priviledges

telnet to mailserver pop3 port:
+OK Hello there. <6274.1219631200@mailserver>
USER password
+OK Password required.
PASS password
+OK logged in.
LIST
+OK POP3 clients that break here, they violate STD53.
.
QUIT
+OK Bye-bye.

Web commands injection through FTP Login in Synology Disk Station - CVE-2010-2453

families.

The disk station product provided by Synology as Network Attached Storage is vulnerable to multiple vulnerabilities including the possibility of 
remote command execution via CSRF (Cross Site Request Forging) through FTP login console. The FTP server is provided as a configurable service 
through web interface which provides backend access to manage the disks station. The problem occurs in the FTP logging mechanism together with the 
admin interface used to view those logs. The FTP console input in the form username and password gets logged in the web application interface. 

This problem was confirmed in the following versions of Synology Disk Station, other versions may be also affected.

Synology Disk Station 2.x


security advisory: AirDroid 1.0.4 beta

        The complete requests decoded looks like this:
        params={"content":"{"number":"123456789","content":"Hello"}"}

    ##### Forbid Multiple Logins
    Even if an attacker has the clear text password by googling it from the md5 hash,
    he will not be able to login as long as the user is logged in himself.
    After a logout of the user without closing the app on the handheld, the attacker could login.
    But it is also possible to do the following from an attacker’s point of view:
        1. Point browser to http://$airdroid_handeld/
        2. Force each HTTP-Request to be sent with the captured cookie (e.g. using an intercepting proxy like burp)
        3. After you sent the login, intercept the servers response which would look like this:

Multiple vulnerabilities in OBM

The following PoC is available:

http://[host]/exportcsv/exportcsv_index.php?action=export_page&module=../../../../tmp/file

Successful exploitation of this vulnerability requires attacker to be registered and logged-in.

2) Input passed via the "sel_domain_id" POST parameter to /obm.php is not properly sanitised before being used in a SQL query.
This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.

The following PoC code is available:

[USN-695-1] shadow vulnerability

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 6.06 LTS:
  login                           1:4.0.13-7ubuntu3.4

Ubuntu 7.10:
  login                           1:4.0.18.1-9ubuntu0.2

Ubuntu 8.04 LTS:

S21SEC-042-en:Cezanne SW Cross-Site Scripting (login required)

- S21Sec Advisory -

##############################################################

Title: Cezanne SW Cross-Site Scripting (login required)
ID: S21SEC-042-en
Severity: Medium
History:
  02.Jan.2008 Vulnerability discovered
Authors:

KwsPHP (Upload) Remote Code Execution Exploit

Faille Discovered By TsukasaGenesis && Ajax
Sploit Coded By Ajax Site: http://www.r57shell.in
*/
if($argc<9){
        print "---KwsPHP All Version / Remote Code Execution---\n\n";
        print "usage: kwsphpsploit.php -url <url> -login <login> -pass <pass> -email <email> -file <file> [-id <id>]\n\n";
        print "Url url of KwsPHP script : Ex : www.example.com/kwsphp/\n";
        print "Login       your account's login ( need to be allow to upload )\n";
        print "Pass        account's password\n";
        print "Email       account's email\n";
        print "File        PHP script upload and execute\n";

TWSL2011-008: Focus Stealing Vulnerability in Android

which app is currently running in the foreground, and 2) display an
Activity
defined in its own app (ie, not the current foreground app).

These two "features" combine to allow a malicious developer to run a
service that looks for apps it knows how to attack, and display a login
screen to the user when those apps run. For example, when the user opens an
app which requires a login, the malicious service displays a screen that
looks identical to the legitimate login screen. Android gives no indication
that the login screen actually belongs to a different app, and the
Activity-switching animation would be the same whether the real app had

PR07-44: XSS on RSA Authentication Agent login page

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

PR07-44: XSS on RSA Authentication Agent login page

Vulnerability found: 5th December 2007

Vendor informed: 13th December 2007

Severity: Medium-high

PR07-44: XSS on RSA Authentication Agent login page

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

PR07-44: XSS on RSA Authentication Agent login page

Vulnerability found: 5th December 2007

Vendor informed: 13th December 2007

Severity: Medium-high

PR07-44: XSS on RSA Authentication Agent login page

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

PR07-44: XSS on RSA Authentication Agent login page

Vulnerability found: 5th December 2007

Vendor informed: 13th December 2007

Severity: Medium-high

Multiple vulnerabilities in LineWeb 1.0.5

LineWeb it's a web-app to manage Lineage 2 private severs, a very known mmorpg, and allows to do action such as:

Main Features:
- Register
- Login
- Quick Login Function
- Quick statistics function (server status, game server status, online players)
- Statistics (login server status, game server status, players online, total accounts, total characters, total gm characters, total clans)

Administrator Features:

PR07-44: XSS on RSA Authentication Agent login page

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

PR07-44: XSS on RSA Authentication Agent login page

Vulnerability found: 5th December 2007

Vendor informed: 13th December 2007

Severity: Medium-high

Family Connections <= 1.8.2 - Remote Shell Upload Exploit

        
        ./rsue localhost /fcms/ user password

        [*] Connecting...
        [+] Connected
        [*] Send login...
        [+] Login Successful
        [+] Uploading...
        [+] Shell uploaded
        [+] Connection closed
        

IBM BladeCenter Advanced Management Module Multiple vulnerabilities

               Main application: BPET36H
               Released: 03-20-08
               Rev:  54
         Risk: Low - Moderate
               High if Web Access is in active use and
               access to login page is unrestricted
Vendor Status: Vendor notified, patch available.
   References: http://www.louhinetworks.fi/advisory/ibm_090409.txt

Affected devices (from vendor):
  IBM BladeCenter E (1881, 7967, 8677)

Rittal CMC-TC Processing Unit II multiple vulnerabilities

    client-side scripts to victim's browser by creating suitable links.

    This vulnerability cannot be used for session hijacking, because
    CMC-TC PU II requires each valid request to contain current session
    ID as URL parameter. Requests without session ID are redirected to
    the login page. Therefore only phishing-type attacks or attacks
    against user's browser are possible.

    Successful exploitation requires that attacker can lure or force
    the user to follow the malicious link.


Seeker Advisory: Insecure Redirect in .NET Form Authentication - Redirect From Login Mechanism (ReturnURL Parameter)

===========
 I. Overview
 ===========

An Insecure Redirect vulnerability has been identified in the .NET Form
Authentication - in the Redirect From Login mechanism. This
vulnerability allows an attacker to craft links that contain redirects
to malicious sites in the ReturnURL parameter. 

The exploitation technique detailed in this document bypasses the
CrossAppRedirects restriction and was successfully performed on

VMware poor guest isolation design

*Summary*

VMware VIX API 1.1 supports an option that allows users with privileges
on the host machine to execute programs on a guest operating system
under the identity of a user currently logged into the guest. For
example, if user A powers on a virtual machine (VM) and logs into the
guest operating system, then a user B who has privilege on the host
machine to connect to that VM can also write scripts that will
anonymously run programs in the VM guest operating system as user A.
Note that the only users who can access the VM this way are either the

Exploit for vBulletin "obscure" XSS (3.7.1 & 3.6.10)

rather easy XSS:

http://localhost/vB3/admincp/index.php?redirect={XSS}

Yes, here goes the obscure. What is even better is that the exploit will
work outright if the admin is already logged in; if the admin is not, they
will be required to log in. If you Base64-encode your attack vector using
the data: URI scheme, the XSS survives the login request and activates after
the admin is logged in. A simple example of the above:

http://localhost/vB3/admincp/index.php?redirect=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K

vBulletin 3.7.1 PL1 and lower, vBulletin 3.6.10 PL1: XSS in modcp index

rather easy XSS:

http://localhost/vB3/modcp/index.php?redirect={XSS}

What is even better is that the exploit will work outright if the
admin/moderator is already logged in;
if the admin/moderator is not, they  will be required to log in.
However, if an admin
logs into the MCP, he is also logged into the ACP, allowing the same
exploit as last time
(remote PHP code injection via the hooks system).

vBulletin 3.7.1 PL1 and lower, vBulletin 3.6.10 PL1: XSS in modcp index

rather easy XSS:

http://localhost/vB3/modcp/index.php?redirect={XSS}

What is even better is that the exploit will work outright if the
admin/moderator is already logged in;
if the admin/moderator is not, they  will be required to log in.
However, if an admin
logs into the MCP, he is also logged into the ACP, allowing the same
exploit as last time
(remote PHP code injection via the hooks system).

Updated: VMware poor guest isolation design

*Summary*

VMware VIX API 1.1 supports an option that allows users with privileges
on the host machine to execute programs on a guest operating system
under the identity of a user currently logged into the guest. For
example, if user A powers on a virtual machine (VM) and logs into the
guest operating system, then a user B who has privilege on the host
machine to connect to that VM can also write scripts that will
anonymously run programs in the VM guest operating system as user A.
Note that the only users who can access the VM this way are either the

Flaw in Microsoft Domain Account Caching Allows Local Workstation Admins to Temporarily Escalate Privileges and Login as Cached Domain Admin Accounts (2010-M$-002)

All versions of Microsoft Windows operating systems allow real-time
modifications to the Active Directory cached accounts listing stored
on all Active Directory domain workstations and servers. This allows
domain users that have local administrator privileges on domain assets
to modify their cached accounts to masquerade as other domain users
that have logged in to those domain assets. This will allow local
administrators to temporarily escalate their domain privileges on
domain workstations or servers. If the local administrator masquerades
as an Active Directory Domain Admin account, the modified cached
account is now free to modify system files and user account profiles
using the identity of the Domain Admin's account. This includes

Next Page>>

Copyright © 1995-2013 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!