<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-20515140</id><updated>2011-04-22T07:34:57.096+05:30</updated><title type='text'>News from the Lab</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://rahulmohandas.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20515140/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://rahulmohandas.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Rahul</name><uri>http://www.blogger.com/profile/06671335464960932420</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>9</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-20515140.post-499925789497804605</id><published>2007-12-10T15:53:00.000+05:30</published><updated>2007-12-10T15:56:49.723+05:30</updated><title type='text'>I am Moving!</title><content type='html'>I am moving, the reincarnated website can be found at &lt;br /&gt;&lt;br /&gt;&lt;a href="http://rahulmohandas.wordpress.com/"&gt;http://rahulmohandas.wordpress.com/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20515140-499925789497804605?l=rahulmohandas.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rahulmohandas.blogspot.com/feeds/499925789497804605/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20515140&amp;postID=499925789497804605' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20515140/posts/default/499925789497804605'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20515140/posts/default/499925789497804605'/><link rel='alternate' type='text/html' href='http://rahulmohandas.blogspot.com/2007/12/i-am-moving.html' title='I am Moving!'/><author><name>Rahul</name><uri>http://www.blogger.com/profile/06671335464960932420</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20515140.post-116100828086058105</id><published>2006-10-16T19:38:00.000+05:30</published><updated>2006-11-09T03:21:36.940+05:30</updated><title type='text'>Hacking the Malware– A reverse-engineer’s analysis</title><content type='html'>&lt;p class="MsoNormal" style="text-align: center;"&gt;&lt;span style="font-weight: bold;"&gt;ABSTRACT&lt;/span&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="text-align: justify;"&gt;This paper attempts to document an approach on how the hackers make use of the vulnerabilities to install malicious software on the vulnerable machine. A comprehensive reverse code engineered analysis of the malicious software (Win32.Qucan.a) and the various protection schemes against the worm by various security products are also discussed.&lt;/p&gt;&lt;p class="MsoBodyText2"&gt;I hope this document will help the Malware researchers, Intrusion Analysts and other Security professionals to conduct a more viable and comprehensive research.&lt;/p&gt;&lt;p&gt;The complete paper can be downloaded from &lt;a href="http://websamba.com/forever_rahul/hacking_the_malware.pdf"&gt;&lt;br /&gt;&lt;/a&gt;&lt;a href="http://geocities.com/rahulmohandas/hacking_the_malware.pdf"&gt;http://geocities.com/rahulmohandas/hacking_the_malware.pdf&lt;/a&gt;&lt;/p&gt;&lt;p&gt;MD5: F875DADCAD00792D753CC96BD57E0F72&lt;/p&gt;&lt;p&gt;                                        or&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.websamba.com/forever_rahul/hacking_the_malware.zip"&gt;http://websamba.com/forever_rahul/hacking_the_malware.zip&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;MD5(zip file): 5562F1A86DDC447A14D7763FF4C8D85D&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20515140-116100828086058105?l=rahulmohandas.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rahulmohandas.blogspot.com/feeds/116100828086058105/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20515140&amp;postID=116100828086058105' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20515140/posts/default/116100828086058105'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20515140/posts/default/116100828086058105'/><link rel='alternate' type='text/html' href='http://rahulmohandas.blogspot.com/2006/10/hacking-malware-reverse-engineers.html' title='Hacking the Malware– A reverse-engineer’s analysis'/><author><name>Rahul</name><uri>http://www.blogger.com/profile/06671335464960932420</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20515140.post-116100241824878893</id><published>2006-10-16T18:08:00.000+05:30</published><updated>2006-10-26T22:44:54.256+05:30</updated><title type='text'>RockLiffe MailSite wconsole.dll Denial of Service/Script Injection Vulnerability</title><content type='html'>&lt;p style="font-family: arial;"&gt;&lt;span style=";font-size:100%;" &gt;OS2A ID: OS2A_1004                              Status&lt;br /&gt;                                           01/06/2006 Issue Discovered&lt;br /&gt;                                           01/06/2006 Reported to the vendor&lt;br /&gt;                                           01/19/2006 Patch Released&lt;br /&gt;                                           01/20/2006 Advisory Released&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="font-family: arial;"&gt;&lt;span style=";font-size:100%;" &gt;Class: Denial of Service / Script Injection     Severity: CRITICAL&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="font-family: arial;"&gt;&lt;span style=";font-size:100%;" &gt;&lt;span style="font-weight: bold;"&gt;Overview: &lt;/span&gt;&lt;br /&gt;Rockliffe's MailSite is a program for providing access to email&lt;br /&gt;accounts on Microsoft Windows operating systems. MailSite HTTP Mail management&lt;br /&gt;agent could allow a remote attacker to cause a denial of service or&lt;br /&gt;execute arbitrary script code.&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="font-family: arial;"&gt;&lt;span style=";font-size:100%;" &gt;&lt;span style="font-weight: bold;"&gt;Description: &lt;/span&gt;&lt;br /&gt;1. MailSite HTTP Mail management agent 7.0.3.1 version could allow a remote&lt;br /&gt;attacker cause a denial of service. A bug in the input validation routine&lt;br /&gt;in httpma causes the svchost process to consume more CPU cycles thus&lt;br /&gt;impacting Mailsite HTTP Management agent and ultimately crashing the service.&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="font-family: arial;"&gt;&lt;span style=";font-size:100%;" &gt;2. MailSite HTTP Mail management agent 6.x and 5.x could allow a remote&lt;br /&gt;attacker to inject arbitrary script code. This vulnerability is caused&lt;br /&gt;due to a design error in the wconsole.dll. This dll file contains html&lt;br /&gt;code embedded in it which is not properly sanitizing the user-input.&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="font-family: arial;"&gt;&lt;span style=";font-size:100%;" &gt;&lt;span style="font-weight: bold;"&gt;Impact: &lt;/span&gt;&lt;br /&gt;1. Remote attackers can exploit this issue to trigger a denial of service&lt;br /&gt;condition.&lt;br /&gt;2. An attacker may leverage this issue to have arbitrary script code&lt;br /&gt;executed in the browser in the context of the affected site.&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="font-family: arial;"&gt;&lt;span style=";font-size:100%;" &gt;&lt;span style="font-weight: bold;"&gt;Affected Software(s):&lt;/span&gt;&lt;br /&gt;MailSite 7.0.3.1 and prior&lt;br /&gt;MailSite 6.1.22 and prior&lt;br /&gt;MailSite 5.x&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="font-family: arial;"&gt;&lt;span style=";font-size:100%;" &gt;&lt;span style="font-weight: bold;"&gt;Affected platform(s): &lt;/span&gt;&lt;br /&gt;Windows (Any)&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="font-family: arial;"&gt;&lt;span style=";font-size:100%;" &gt;&lt;span style="font-weight: bold;"&gt;Exploit/Proof of Concept: &lt;/span&gt;&lt;br /&gt;For 7.x series&lt;br /&gt;http://www.example.com:90/CGI-BIN/WCONSOLE.DLL?Authenticate|cmd&lt;br /&gt;Any special characters passed to the parameters in the wconsole.dll&lt;br /&gt;triggers denial of service.&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="font-family: arial;"&gt;&lt;span style=";font-size:100%;" &gt; For 6.x &amp; 5.x series&lt;br /&gt;http://www.example.com:90/CGI-BIN/WCONSOLE.DLL?%3Cscript%3Ealert&lt;br /&gt;(document.cookie)%3C/script%3E&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="font-family: arial;"&gt;&lt;span style=";font-size:100%;" &gt;&lt;span style="font-weight: bold;"&gt;Solution: &lt;/span&gt;&lt;br /&gt;For 7.x series apply the following patch.&lt;br /&gt;ftp://ftp.rockliffe.com/MailSite/Latest/Hotfixes/&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;span style="font-family: arial;font-family:arial;font-size:100%;"  &gt; For 6.x series apply the following patch&lt;br /&gt;ftp://ftp.rockliffe.com/MailSite/6.1.22/Hotfixes/&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Reference:&lt;/span&gt;&lt;br /&gt;&lt;a href="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0750.html"&gt;http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0750.html&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20515140-116100241824878893?l=rahulmohandas.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rahulmohandas.blogspot.com/feeds/116100241824878893/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20515140&amp;postID=116100241824878893' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20515140/posts/default/116100241824878893'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20515140/posts/default/116100241824878893'/><link rel='alternate' type='text/html' href='http://rahulmohandas.blogspot.com/2006/10/rockliffe-mailsite-wconsoledll-denial.html' title='RockLiffe MailSite wconsole.dll Denial of Service/Script Injection Vulnerability'/><author><name>Rahul</name><uri>http://www.blogger.com/profile/06671335464960932420</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20515140.post-116100195286599974</id><published>2006-10-16T17:58:00.000+05:30</published><updated>2006-10-16T18:19:47.056+05:30</updated><title type='text'>myBloggie SQL Injection/Privilege Escalation Vulnerability</title><content type='html'>&lt;pre face="arial"&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div style="text-align: left; font-family: arial;"&gt;OS2A ID: OS2A_1002&lt;br /&gt;&lt;br /&gt;Status&lt;br /&gt;  9/1/2005 Issue Discovered&lt;br /&gt;  9/2/2005 Reported to the vendor&lt;br /&gt;  9/3/2005 Patch Released   &lt;br /&gt;  9/5/2005 Advisory Released&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;pre style="font-family: arial;"&gt;&lt;br /&gt;Class: SQL Injection    Severity: CRITICAL&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Overview:&lt;/span&gt;&lt;br /&gt;myBloggie is a Weblog system built using PHP &amp; mySQL. myBloggie&lt;br /&gt;versions2.1.3-beta and prior are vulnerable to SQL injection vulnerability&lt;br /&gt;causedby improper validation of user-supplied inputs. This vulnerability&lt;br /&gt;can be exploited to bypass authentication mechanism, escalate the&lt;br /&gt;privileges toadministrator level and also made to reveal system&lt;br /&gt;specific information.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Description:&lt;/span&gt;&lt;br /&gt;User supplied credential inputs ('$username' and '$passwd') are not&lt;br /&gt;sanitized in login.php before subjecting them to SQL query.&lt;br /&gt;&lt;br /&gt;&lt;-------------------login.php snippet-----------------------------&gt;&lt;br /&gt;&lt;br /&gt;if (isset($_POST['username'])) {&lt;br /&gt;$username=$_POST['username'];&lt;br /&gt;} else $username="";&lt;br /&gt;&lt;br /&gt;$result = mysql_query( "SELECT user FROM ".USER_TBL." WHERE user=&lt;br /&gt;'$username'    AND password='$passwd'" ) or error( mysql_error() );&lt;br /&gt;&lt;br /&gt;&lt;-----------------------------------------------------------------&gt;&lt;br /&gt;&lt;br /&gt;This can be exploited in multiple ways,&lt;br /&gt;1. Authentication Bypass&lt;br /&gt;A malicious user can log on to the weblog system without submitting&lt;br /&gt;thepassword by placing queries such as this "admin' OR 'x'='x" in&lt;br /&gt;the User Name field.&lt;br /&gt;&lt;br /&gt;2. Privilege Escalation.&lt;br /&gt;When a non-administrative user submits, for example "user1' OR 'x'='x"&lt;br /&gt;into the User Name field, administrative privileges will be granted.&lt;br /&gt;&lt;br /&gt;3. Path Disclosure.&lt;br /&gt;Path information can be made to disclose in error pages by passing&lt;br /&gt;invalid query to User Name field of login.php.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Impact:&lt;/span&gt;&lt;br /&gt;Successful exploitation can result in a compromise of the application,&lt;br /&gt;disclosure of system specific information, or permit an attacker to&lt;br /&gt;exploit vulnerabilities in the underlying database implementation.&lt;br /&gt;An attacker can also exploit this vulnerability to elevate privileges&lt;br /&gt;within the affected system.&lt;br /&gt;&lt;br /&gt;Affected Systems:&lt;br /&gt;myBloggie 2.1.3-beta and prior.&lt;br /&gt;Linux (Any), Unix (Any), Windows (Any)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Exploit:&lt;/span&gt;&lt;br /&gt;1. POST &lt;a rel="nofollow" href="http://example.com/mybloggie/login.php?username=admin"&gt;http://example.com/mybloggie/login.php?username=admin&lt;/a&gt;' OR&lt;br /&gt;'x'='x&lt;br /&gt;2. POST &lt;a rel="nofollow" href="http://example.com/mybloggie/login.php?username=normal_user"&gt;http://example.com/mybloggie/login.php?username=normal_user&lt;/a&gt;&lt;br /&gt;' OR 'one'='one&lt;br /&gt;3. POST &lt;a rel="nofollow" href="http://example.com/mybloggie/login.php?username="&gt;http://example.com/mybloggie/login.php?username=&lt;/a&gt;'1=1 --&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Solution:&lt;/span&gt;&lt;br /&gt;Patch: &lt;a rel="nofollow" href="http://mywebland.com/forums/showtopic.php?t=399"&gt;http://mywebland.com/forums/showtopic.php?t=399&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Reference:&lt;br /&gt;&lt;/span&gt;&lt;a href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112607358831963&amp;amp;w=2"&gt;http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112607358831963&amp;amp;w=2&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/pre&gt;&lt;span style="font-family:arial;"&gt; &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20515140-116100195286599974?l=rahulmohandas.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rahulmohandas.blogspot.com/feeds/116100195286599974/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20515140&amp;postID=116100195286599974' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20515140/posts/default/116100195286599974'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20515140/posts/default/116100195286599974'/><link rel='alternate' type='text/html' href='http://rahulmohandas.blogspot.com/2006/10/mybloggie-sql-injectionprivilege.html' title='myBloggie SQL Injection/Privilege Escalation Vulnerability'/><author><name>Rahul</name><uri>http://www.blogger.com/profile/06671335464960932420</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20515140.post-116100160507371421</id><published>2006-10-16T17:53:00.000+05:30</published><updated>2006-10-16T17:56:45.106+05:30</updated><title type='text'>Hesk Session ID Validation Vulnerability</title><content type='html'>&lt;p style="font-family: arial;"&gt;OS2A ID: OS2A_1003    Status&lt;br /&gt;                                                9/13/2005 Issue Discovered&lt;br /&gt;                                                9/14/2005 Reported to the vendor&lt;br /&gt;                                                9/18/2005 Patch Released&lt;br /&gt;                                                9/20/2005 Advisory Released&lt;br /&gt;                                                        &lt;br /&gt;&lt;/p&gt;&lt;p style="font-family: arial;"&gt;Class: Authentication Bypass   Severity: CRITICAL&lt;br /&gt;&lt;/p&gt;&lt;p style="font-family: arial;"&gt;&lt;span style="font-weight: bold;"&gt;Overview: &lt;/span&gt;&lt;br /&gt;Hesk is a PHP based help desk software that runs with a MySQL database. &lt;br /&gt;It allows to setup a ticket based support system (helpdesk) for websites.&lt;br /&gt;Hesk versions 0.93 and prior are vulnerable to authentication bypass and path &lt;br /&gt;disclosure vulnerabilities caused due to improper validation of the HTTP &lt;br /&gt;header. This vulnerability can be exploited to bypass authentication &lt;br /&gt;mechanism, and also made to reveal system specific information. &lt;br /&gt; &lt;br /&gt;&lt;/p&gt;&lt;p style="font-family: arial;"&gt;&lt;span style="font-weight: bold;"&gt;Description: &lt;/span&gt;&lt;br /&gt;Multiple vulnerabilities exist in Hesk ticket based support system.&lt;br /&gt;&lt;/p&gt;&lt;p style="font-family: arial;"&gt;1. Authentication Bypass&lt;br /&gt;   The 'PHPSESSID', Session ID parameter in the HTTP header is not properly &lt;br /&gt;   validated. A malicious user can log in to the Administrator account by &lt;br /&gt;   sending a random value to 'PHPSESSID' parameter and posting it to &lt;br /&gt;   admin.php. This Session ID can then be utilized to access administrative &lt;br /&gt;   control panel. &lt;br /&gt; &lt;br /&gt;   This is similar to a previously reported vulnerability where invalid &lt;br /&gt;   User ID and Password were submitted. In this case, a randomly chosen &lt;br /&gt;   Session ID is sent along with the login request. &lt;br /&gt;   &lt;br /&gt;2. Path Disclosure.&lt;br /&gt;   Path information can be made to disclose in error pages by passing invalid &lt;br /&gt;   metacharacters such as "'" or "&lt;" to 'PHPSESSID' field of the HTTP header.&lt;br /&gt;   &lt;br /&gt;&lt;/p&gt;&lt;p style="font-family: arial;"&gt;&lt;span style="font-weight: bold;"&gt;Impact: &lt;/span&gt;&lt;br /&gt;Successful exploitation can result in a compromise of the application, &lt;br /&gt;disclosure of system specific information.&lt;br /&gt;&lt;/p&gt;&lt;p style="font-family: arial;"&gt;&lt;span style="font-weight: bold;"&gt;Affected Systems: &lt;/span&gt;&lt;br /&gt;Hesk 0.93 and prior.&lt;br /&gt;Linux (Any), Unix (Any), Windows (Any)&lt;br /&gt;&lt;/p&gt;&lt;p style="font-family: arial;"&gt;&lt;span style="font-weight: bold;"&gt;Exploit: &lt;/span&gt;&lt;br /&gt;1. HTTP POST request with randomly chosen Session ID:&lt;br /&gt;POST admin.php +&lt;br /&gt;("Host: host_ip&lt;br /&gt;  User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.7.7) &lt;br /&gt;  Accept: text/xml,application/xml,application/xhtml+xml,text/html&lt;br /&gt;  Accept-Language: en-us,en;q=0.5&lt;br /&gt;  Accept-Encoding: gzip,deflate&lt;br /&gt;  Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7&lt;br /&gt;  Keep-Alive: 300&lt;br /&gt;  Connection: keep-alive&lt;br /&gt;  Referer: &lt;a href="http://host_ip/hesk/admin.php"&gt;http://host_ip/hesk/admin.php&lt;/a&gt;&lt;br /&gt;  Cookie: PHPSESSID=12345                             &lt;!-- Random Session ID --!&gt;&lt;br /&gt;  Content-Type: application/x-www-form-urlencoded&lt;br /&gt;  Content-Length: 26&lt;br /&gt;  user=1&amp;pass=sdfd&amp;amp;a=do_login");&lt;br /&gt; &lt;br /&gt;2. GET request to administrative control panel:&lt;br /&gt;GET admin_main.php +&lt;br /&gt;("Host: host_ip&lt;br /&gt;  User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.7.7) &lt;br /&gt;  Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain&lt;br /&gt;  Accept-Language: en-us,en;q=0.5&lt;br /&gt;  Accept-Encoding: gzip,deflate&lt;br /&gt;  Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7&lt;br /&gt;  Keep-Alive: 300&lt;br /&gt;  Connection: keep-alive&lt;br /&gt;  Cookie: PHPSESSID=12345")                            &lt;!-- Session ID --!&gt;&lt;br /&gt;&lt;/p&gt;&lt;span style="font-family: arial; font-weight: bold;"&gt;Solution:&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: arial;"&gt;       Patch:  &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;         &lt;/span&gt;&lt;a style="font-family: arial;" href="http://www.phpjunkyard.com/extras/hesk_0931_patch.zip"&gt;http://www.phpjunkyard.com/extras/hesk_0931_patch.zip&lt;/a&gt;&lt;span style="font-family: arial;"&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;         OR Hesk 0.93.1 from &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;         &lt;/span&gt;&lt;a style="font-family: arial;" href="http://www.phpjunkyard.com/free-helpdesk-software.php"&gt;http://www.phpjunkyard.com/free-helpdesk-software.php&lt;/a&gt;&lt;span style="font-family: arial;"&gt;  &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial; font-weight: bold;"&gt;Reference:&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a style="font-family: arial;" href="http://seclists.org/bugtraq/2005/Sep/0242.html"&gt;http://seclists.org/bugtraq/2005/Sep/0242.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20515140-116100160507371421?l=rahulmohandas.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rahulmohandas.blogspot.com/feeds/116100160507371421/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20515140&amp;postID=116100160507371421' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20515140/posts/default/116100160507371421'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20515140/posts/default/116100160507371421'/><link rel='alternate' type='text/html' href='http://rahulmohandas.blogspot.com/2006/10/hesk-session-id-validation.html' title='Hesk Session ID Validation Vulnerability'/><author><name>Rahul</name><uri>http://www.blogger.com/profile/06671335464960932420</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20515140.post-116099926537964035</id><published>2006-10-16T17:13:00.000+05:30</published><updated>2006-10-16T17:50:13.133+05:30</updated><title type='text'>ePing Arbitrary File CreationCommand Execution Vulnerability</title><content type='html'>&lt;div face="times new roman" style="text-align: justify; font-family: arial;"&gt;&lt;pre&gt;OS2A ID: OS2A_1001    Status      Published: 08/04/2005 &lt;br /&gt;Updated  : 08/05/2005&lt;br /&gt;Patch Released&lt;br /&gt;&lt;br /&gt;Class: File Creation/Command Execution&lt;br /&gt;Severity: CRITICAL&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;/div&gt;&lt;span style="font-weight: bold; font-family: arial;font-family:times new roman;" &gt;Overview:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;font-family:times new roman;" &gt;ePing is a ping utility plugin for e107, a PHP-based content&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;font-family:times new roman;" &gt;management system that uses a MySQL backend database. ePing&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;font-family:times new roman;" &gt;versions 1.02 and prior are vulnerable to a file creation&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;font-family:times new roman;" &gt;vulnerability caused by improper validation of user-supplied&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;font-family:times new roman;" &gt;input in the doping.php script. A remote attacker exploiting&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;font-family:times new roman;" &gt;this vulnerability could then create an arbitrary file in the&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;font-family:times new roman;" &gt;webserver, pipe multiple system commands in the eping_host&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;font-family:times new roman;" &gt;or the eping_count parameters of the doping.php script, which&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;font-family:times new roman;" &gt;would be executed within the security context of the hosting&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;font-family:times new roman;" &gt;site.&lt;/span&gt;&lt;br /&gt;&lt;div style="text-align: justify; font-family: arial;"&gt;&lt;pre&gt;&lt;br /&gt;eTrace, another utility plugin for e107 has similar&lt;br /&gt;vulnerabilities.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Description:&lt;/span&gt;&lt;br /&gt;e107 portal's eping plugin 1.02 and prior is prone to remote&lt;br /&gt;command execution vulnerability. This vulnerability exists&lt;br /&gt;due to output redirection operators like '&gt;', '|', '&amp;' are&lt;br /&gt;not being sanitized in eping_host,eping_count parameters in&lt;br /&gt;the doping.php script.&lt;br /&gt;&lt;br /&gt;eping_host has a validate function in functions.php which does&lt;br /&gt;not consider the above mentioned case.&lt;br /&gt;&lt;br /&gt;eping_count has no validation logic. It accepts the above&lt;br /&gt;mentioned system meaningful characters.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Impact:&lt;/span&gt;&lt;br /&gt;A remote user can execute any command using '|' character or&lt;br /&gt;create a file with malicious executable code with '&gt;' character.&lt;br /&gt;Execution of arbitrary command or creation of arbitrary files&lt;br /&gt;can lead to, Denial of service, Disclosure or modification of&lt;br /&gt;system information or Execution of arbitrary code.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Affected Systems:&lt;/span&gt;&lt;br /&gt;ePing version 1.02 and prior&lt;br /&gt;Linux (Any), Unix (Any), Windows (Any)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Exploit:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;a.&lt;br /&gt;&lt;a href="http://example.com/e107/e107_plugins/eping/doping.php?eping_cmd=ping%20-n&amp;eping_host=1"&gt;http://example.com/e107/e107_plugins/eping/doping.php?eping_cmd=ping&lt;/a&gt;&lt;br /&gt;&lt;a href="http://example.com/e107/e107_plugins/eping/doping.php?eping_cmd=ping%20-n&amp;amp;eping_host=1"&gt;%20-n&amp;eping_host=1&lt;/a&gt;27.0.0.1&amp;amp;eping_count=2%20%22%3C?php%20system(%94cmd&lt;br /&gt;.exe%94)?%3E%22%20%3Etest.php&lt;br /&gt;&lt;br /&gt;b.&lt;br /&gt;&lt;a href="http://example.com/e107/e107_plugins/eping/doping.php?eping_cmd=ping%20-n&amp;eping_host=1"&gt;http://example.com/e107/e107_plugins/eping/doping.php?eping_cmd=ping&lt;/a&gt;&lt;br /&gt;&lt;a href="http://example.com/e107/e107_plugins/eping/doping.php?eping_cmd=ping%20-n&amp;amp;eping_host=1"&gt;%20-n&amp;eping_host=1&lt;/a&gt;27.0.0.1&amp;amp;eping_count=2|dir&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Solution:&lt;/span&gt;&lt;br /&gt;Patch:&lt;br /&gt;Upgrade to the version 1.03 of ePing and eTrace plugins. &lt;/pre&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Reference: &lt;/span&gt;&lt;br /&gt;&lt;a href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112328161319148&amp;amp;w=2"&gt;http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112328161319148&amp;amp;w=2&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20515140-116099926537964035?l=rahulmohandas.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rahulmohandas.blogspot.com/feeds/116099926537964035/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20515140&amp;postID=116099926537964035' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20515140/posts/default/116099926537964035'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20515140/posts/default/116099926537964035'/><link rel='alternate' type='text/html' href='http://rahulmohandas.blogspot.com/2006/10/eping-arbitrary-file-creationcommand.html' title='ePing Arbitrary File CreationCommand Execution Vulnerability'/><author><name>Rahul</name><uri>http://www.blogger.com/profile/06671335464960932420</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20515140.post-113697661609574234</id><published>2006-01-11T16:01:00.000+05:30</published><updated>2006-10-12T00:30:08.386+05:30</updated><title type='text'>Another week!!</title><content type='html'>Anyways the second week since i started with my blog, glad to quote that i succesfully completed the research on Mailsite. Atlast another of OS2A's advisories, the fourth one infact.&lt;br /&gt;Dissected various dll files of Mailsite, what captured my attention was the wconsole.dll, very unusual a dll file is exposed to the user as it is , initial analysis was a cross-scripting vulnerability in Mailsite which was obvious  as the HTML code was embedded in the dll file and whatever script is inserted into the GET request&lt;br /&gt;it is executing in the returning HTMl page response.&lt;br /&gt;Now i downloaded the latest series of Mailsite,(7.0.3) performed the same kind of analysis on the dll files, this time a different observation :-) . Mailsite is not properly sanitizing the input parameters to the GET request&lt;br /&gt;Can you believe what happened?&lt;br /&gt;Yup, a buffer overflow in the HTTPMA service. It causes the svchost process to consume entire cpu cycles&lt;br /&gt;and ultimately crashed the service.A denial of service, the first one of its kind from me.&lt;br /&gt;&lt;br /&gt;Contacted the vendor, waiting them to release the fixes, can't wait to get my advisory out.....&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20515140-113697661609574234?l=rahulmohandas.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rahulmohandas.blogspot.com/feeds/113697661609574234/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20515140&amp;postID=113697661609574234' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20515140/posts/default/113697661609574234'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20515140/posts/default/113697661609574234'/><link rel='alternate' type='text/html' href='http://rahulmohandas.blogspot.com/2006/01/another-week.html' title='Another week!!'/><author><name>Rahul</name><uri>http://www.blogger.com/profile/06671335464960932420</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20515140.post-113644361038017545</id><published>2006-01-05T12:01:00.000+05:30</published><updated>2006-06-02T00:20:30.916+05:30</updated><title type='text'></title><content type='html'>A cool Thursday, late to office, started with the environment setup of my routine tasks,&lt;br /&gt;Got a cisco task to work on. The mailsite express vulnerability i been researching on is still pending.&lt;br /&gt;Initial observation shows a denial of service in the 7.x series of the mail agent, but a cross-site scripting vulnerability in 7.x, 6.x and 5.x versions are evident.&lt;br /&gt;Can't wait to get this done :-)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20515140-113644361038017545?l=rahulmohandas.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rahulmohandas.blogspot.com/feeds/113644361038017545/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20515140&amp;postID=113644361038017545' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20515140/posts/default/113644361038017545'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20515140/posts/default/113644361038017545'/><link rel='alternate' type='text/html' href='http://rahulmohandas.blogspot.com/2006/01/cool-thursday-late-to-office-started.html' title=''/><author><name>Rahul</name><uri>http://www.blogger.com/profile/06671335464960932420</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20515140.post-113636323844669628</id><published>2006-01-04T13:49:00.000+05:30</published><updated>2007-10-14T01:26:21.183+05:30</updated><title type='text'>RAHUL's Blog</title><content type='html'>Welcome to my blog,  guys !!! This blog is here to keep track of my interests in the security space...Have a nice time....&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20515140-113636323844669628?l=rahulmohandas.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rahulmohandas.blogspot.com/feeds/113636323844669628/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20515140&amp;postID=113636323844669628' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20515140/posts/default/113636323844669628'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20515140/posts/default/113636323844669628'/><link rel='alternate' type='text/html' href='http://rahulmohandas.blogspot.com/2006/01/rahuls-blog.html' title='RAHUL&apos;s Blog'/><author><name>Rahul</name><uri>http://www.blogger.com/profile/06671335464960932420</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry></feed>
