hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

qcred11
QUOTE
Application: ParaChat Server
              http://www.parachat.com/

Version: 5.5
Bug: directory traversal
Date: 28-Sep-2004
Author: Donato Ferrante
              e-mail: fdonato_at_autistici.org
              xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx


1. Description
2. The bug
3. The code
4. The fix

xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

----------------
1. Description:
----------------


Vendor's Description:


"ParaChat Server v5.5 is a fast, easy and affordable way to host and
manage your own real-time communication software - for one web site,
or for multiple web sites."

xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

------------
2. The bug:
------------


The server is not able to manage the sequence "..%5C/", that is
equal to "..\/", this lets an attacker to navigate through the
victim system simply using a web browser.


xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx


-------------
3. The code:
-------------


To test the vulnerability:


http://[host]:7877/..%5C/..%5C/

xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx


------------
4. The fix:
------------

Vendor was contacted.
Bug will be fixed in the next version.


xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx



Source: http://seclists.org/lists/bugtraq/2004/Sep/0418.html
ShouiZen
i put this tools
on my server i tested (I have xp icrosoft Windows XP [version 5.1.2600]) but it ' doesnt work http://ip:7877/..%5C/..%5C/
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.