233
Easy File Sharing Webserver 1.25 Access Control Bypass
HTTP
2004/09/13
Nico 'Triplex' Spicher
Triplex at IT-Helpnet dot de
http://triplex.it-helpnet.de/
http://www.it-helpnet.de/
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
2004/11/14
2.0
Made some slight modifications and enhancements in version 1.1. Corrected the plugin structure and added the accuracy values in 1.2. Improved the pattern matching and introduced the plugin changelog in 2.0
tcp
80
open|send GET /disk_c HTTP/1.0\n\n|sleep|close|pattern_exists HTTP/#.# 200 *
99
This plugin was written with the ATK-Plugin-Creator [http://triplex.it-helpnet.de].
James Bercegay
http://www.gulftech.org
GulfTech Security Research Team
2004/08/24
http://gulftech.org/?node=research&article_id=00045-08242004
Easy File Sharing Webserver 1.2 and 1.25
Missing Authentication
There is no authentication given. An attacker may be able gain elevated access.
If the web server is not used it should be de-installed or de-activated. Install the newest patch or bugfix to solve the problem or upgrade to the latest software version which is not vulnerable anymore (http://www.sharing-file.com). Additionally limit unwanted connections and communications with firewalling.
Approx. 20 minutes
Yes
http://www.securityfocus.com/bid/11034/exploit/
Yes
Yes
Medium
2
8
7
3
11034
Hacking Intern - Angriffe, Strategien, Abwehr, Marc Ruef, Marko Rogge, Uwe Velten and Wolfram Gieseke, November 1, 2002, Data Becker, Düsseldorf, ISBN 381582284X
http://www.securityfocus.com/archive/1/372840