SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow SecurityAlert Database

Arrow  Topic :

Logs visualization in WS_FTP Server Manager 6.1.0.0


Arrow  SecurityAlert : 4799
Arrow  CVE : CVE-2008-5692
Arrow  CVE : CVE-2008-5693
Arrow  CWE : CWE-287
Arrow  SecurityRisk : Medium  Security Risk Medium  (About)
Arrow  Remote Exploit : Yes
Arrow  Local Exploit : No
Arrow  Victim interaction required : No
Arrow  Exploit Available : Yes
Arrow  Credit : Luigi Auriemma
Arrow  Published : 23.12.2008

Arrow  Affected Software : ipswitch:ws_ftp:6.1 and previous versions
ipswitch:ws_ftp:5.05
ipswitch:ws_ftp:2.02
ipswitch:ws_ftp:5.02
ipswitch:ws_ftp:5.03
ipswitch:ws_ftp:5.04
ipswitch:ws_ftp:4.02
ipswitch:ws_ftp:4.01
ipswitch:ws_ftp:1.0.5
ipswitch:ws_ftp:4.00
ipswitch:ws_ftp:3.1.0
ipswitch:ws_ftp:5.00
ipswitch:ws_ftp:3.0
ipswitch:ws_ftp:6.0
ipswitch:ws_ftp:3.0.1
ipswitch:ws_ftp:3.1.1
ipswitch:ws_ftp:3.1.2
ipswitch:ws_ftp:3.1.3
ipswitch:ws_ftp:5.01
ipswitch:ws_ftp:2.03
ipswitch:ws_ftp:3.14
ipswitch:ws_ftp:2.01



Arrow  Advisory Content :  

#######################################################################

Luigi Auriemma

Application: WS_FTP Server Manager
http://www.wsftp.com
Versions: WS_FTP Server <= 6.1.0.0
Platforms: Windows
Bugs: A] authorization bypassing in log visualization
B] ASP source visualization
Exploitation: remote
Date: 06 Feb 2008
Author: Luigi Auriemma
e-mail: aluigi (at) autistici (dot) org [email concealed]
web: aluigi.org

#######################################################################

1) Introduction
2) Bugs
3) The Code
4) Fix

#######################################################################

===============
1) Introduction
===============

WS_FTP Server Manager (aka WS_FTP WebService) is the web administration
interface of the IpSwitch WS_FTP server and runs by default on port 80.

#######################################################################

=======
2) Bugs
=======

-----------------------------------------------
A] authorization bypassing in log visualization
-----------------------------------------------

The FTPLogServer folder available in the WS_FTP WebService is used for
the visualization and the downloading of the log entries collected by
the Logger Server used for any logging operation of the IpSwitch
servers (like both WS_FTP and the same WebService).

Naturally for watching the logs is needed to know the administration
username and password but exists a vulnerability which allows anyone to
gain access to this function of the server.

It's enough to logout from the web server without being logged in and
after this operation is possible to use all the asp files located in
the FTPLogServer folder through a strange account name called
localhostnull.
The vulnerability has been confirmed from both LAN and Internet.

The authorization bypassing is possible only for the ASP files located
in this folder so the management of the FTP server is not touched by
the vulnerability.

---------------------------
B] ASP source visualization
---------------------------

The following small bug is reported here only for thoroughness and has
no impact.
By default it canNOT be defined a vulnerability because the webservice,
although possible due to its directories structure (in short the WS_FTP
stuff is all in the WSFTPSVR folder so the rest of the root path of the
web server can be used for anything else), can't be considered a
"classical" web server where using custom contents.

Anyway if on the web server are in use custom ASP files a person can
see their content simply adding a dot at the end of the URL like in the
following examples of some pre-existent script files without the need
of being logged in:

http://SERVER/WSFTPSVR/login.asp.
http://SERVER/WSFTPSVR/FTPLogServer/LogViewer.asp.
http://SERVER/WSFTPSVR/FTP/ViewCert.asp.

#######################################################################

===========
3) The Code
===========

The following are the URLs to use in sequence for watching the logs:

http://SERVER/WSFTPSVR/FTPLogServer/login.asp?action=logLogout
http://SERVER/WSFTPSVR/FTPLogServer/LogViewer.asp

#######################################################################

======
4) Fix
======

No fix

#######################################################################

---
Luigi Auriemma
http://aluigi.org



Arrow  References :

http://www.securityfocus.com/bid/27654
http://www.securityfocus.com/archive/1/archive/1/487697/100/200/threaded
http://www.securityfocus.com/archive/1/archive/1/487686/100/200/threaded
http://www.frsirt.com/english/advisories/2008/0473
http://secunia.com/advisories/28822
http://docs.ipswitch.com/WS_FTP_Server611/ReleaseNotes/index.htm?k_id=ipswitch_ftp_documents_worldwide_ws_ftpserverv611releasenotes#link12
http://aluigi.altervista.org/adv/wsftpweblog-adv.txt




Arrow  Feedback :

If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Alert

libc/fnmatch(3) DoS

Security Risk Medium- 2011-05-13

Allow attacker to denial of service apache 2.2.17 server

Apache RSS Apache Alert

» Apache HTTP Server Denial
   of Service Vulnerability

» Multiple Vendors
   libc/fnmatch(3) DoS (incl
   apache poc)

» Apache Continuum
   cross-site scripting
   vulnerability

» Apache Tomcat DoS
   Vulnerability

PHP RSS PHP Alert

» PHP Hashtables Denial of
   Service

» PHP 5.3.6 multiple null
   pointer dereference

» PHP 5.3.6 ZipArchive
   invalid use glob(3)

» libzip 0.9.3
   _zip_name_locate NULL
   Pointer Dereference (incl
   PHP 5.3.5)

ADT

Protect your family and valuables with Home Security Systems

Copyright © SecurityReason.com. All Rights Reserved.