Информационная безопасность
[RU] switch to
English Version



Дополнительная информация

  Ежедневная сводка ошибок в Web-приложениях (PHP, ASP, JSP, CGI, Perl )

  Adult Script Unauthorized Administrative Access Exploit

  Information disclosure vulnerabilities in WordPress

  Wordpress - Broken Access Control

  PHP RPG - Sql Injection and Session Information Disclosure.

From:th3.r00k_(at)_gmail.com <th3.r00k_(at)_gmail.com>
Date:16 декабря 2007 г.
Subject:Anon Proxy Server - Remote Code Execution

By Michael Brooks

Vulnerability type: Multiple Remote System commands execution.

Software: Anon Proxy Server

Home page:http://sourceforge.net/projects/anonproxyserver/

Affects version: 0.100



Example exploit:

http://127.0.0.1/anon_proxy_server_0.100/diagdns.php?host=google.com%5C%2
7+%26%26+cat+%2Fetc%2Fpasswd+%23




A virtually identical flaw exists in diagconnect.php however it takes longer to execute.



Anon Proxy Server forces magic_quotes_gpc=on,  However magic_quotes_gpc does not protect the system()  function from taint.  For protection you should use the escapeshellarg() function. Removing diagdns.php and diagconnect.php is the best temporary solution.  Also magic_quotes_gpc is being removed in php6,  so Anon Proxy Server will have to revamp there security.



Peace

О сайте | Условия использования
© SecurityVulns, 3APA3A, Владимир Дубровин
Нижний Новгород

 
 



Rating@Mail.ru
test server