积极预防 及时发现
快速响应 力保恢复
KaZaA, Grokster和Morpheus是基于FastTrack P2P技术的文件共享客户端...
发布时间:2002-03-11 信息来源:管理员

CNCVE编号:CNCVE-20020044 CVE编号: 安全级别:高 漏洞中文描述: KaZaA, Grokster和Morpheus是基于FastTrack P2P技术的文件共享客户端,它们运行于Microsoft Windows平台,并已经移植到Linux平台。用户可以通过受影响客户端的消息服务伪造一个HTTP GET头来伪装成一个已经存在的用户。不过伪造头的主机和用户名必须是合法的。客户端的消息服务默认在1214端口监听,即使没有任何连接到该服务。基于FastTrack P3P技术的文件共享客户端如果有消息功能可能都会有这个漏洞。这是一个安全漏洞,因为访问控制是基于客户端的身份验证。 漏洞英文描述: KaZaA, Grokster and Morpheus are file-sharing clients based on FastTrack P2P technologies. They will run on Microsoft Windows 9x/ME/NT/2000/XP systems. Ports also exist for variants of the Linux operating system. It is possible for a user to craft a raw fake HTTP GET header to spoof the identity of an another existing user via the messaging service offered by vulnerable clients. The host and username in the header most both by valid for this to work. Clients listen for messages on port 1214 by default, even when they are not actively connected to the service. Any versions of file-sharing clients based on FastTrack P2P technologies which include the messaging functionality should be considered prone to this issue. This is a security vulnerability because access control is based on client identities, supplied in the request headers. Attackers may spoof their identity to exploit BugTraq ID 4122 "FastTrack P2P Technology Message Service Denial Of Service Vulnerability". 漏洞参考: http://www.kazaa.com/ http://www.grokster.com/ http://www.musiccity.com/ 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:输入有效性检查错误