233 Easy File Sharing Webserver 1.25 Access Control Bypass HTTP 2004/09/13 Nico 'Triplex' Spicher Triplex at IT-Helpnet dot de http://triplex.it-helpnet.de/ http://www.it-helpnet.de/ Marc Ruef marc dot ruef at computec dot ch http://www.computec.ch computec.ch 2004/11/14 2.0 Made some slight modifications and enhancements in version 1.1. Corrected the plugin structure and added the accuracy values in 1.2. Improved the pattern matching and introduced the plugin changelog in 2.0 tcp 80 open|send GET /disk_c HTTP/1.0\n\n|sleep|close|pattern_exists HTTP/#.# 200 * 99 This plugin was written with the ATK-Plugin-Creator [http://triplex.it-helpnet.de]. James Bercegay http://www.gulftech.org GulfTech Security Research Team 2004/08/24 http://gulftech.org/?node=research&article_id=00045-08242004 Easy File Sharing Webserver 1.2 and 1.25 Missing Authentication There is no authentication given. An attacker may be able gain elevated access. If the web server is not used it should be de-installed or de-activated. Install the newest patch or bugfix to solve the problem or upgrade to the latest software version which is not vulnerable anymore (http://www.sharing-file.com). Additionally limit unwanted connections and communications with firewalling. Approx. 20 minutes Yes http://www.securityfocus.com/bid/11034/exploit/ Yes Yes Medium 2 8 7 3 11034 Hacking Intern - Angriffe, Strategien, Abwehr, Marc Ruef, Marko Rogge, Uwe Velten and Wolfram Gieseke, November 1, 2002, Data Becker, Düsseldorf, ISBN 381582284X http://www.securityfocus.com/archive/1/372840