183 Keene Digital Media Server prior 1.0.3 Adminsitrative Authentication Bypass HTTP 2004/09/07 Nico 'Triplex' Spicher Triplex at IT-Helpnet dot de http://triplex.it-helpnet.de/ http://www.it-helpnet.de/ Marc Ruef marc dot ruef at computec dot ch http://www.computec.ch computec.ch 2004/11/13 1.2 Made some slight modifications in version 1.1. Corrected the plugin structure and added the accuracy values in 1.2 tcp 8080 open|send GET /dms/adminusers.kspx HTTP/1.0\n\n|sleep|close|pattern_exists 200 85 This plugin was written with the ATK-Plugin-Creator [http://triplex.it-helpnet.de]. Ziv Kamir vulncode at yahoo dot com 2004/08/12 http://secunia.com/advisories/12272 Keene Digital Media Server 1.0.2 and 1.0.3 Keene Digital Media Server 1.0.4 and newer Configuration Keene Digital Media Server contains a flaw that may allow a malicious user to bypass authentication used to protect the adminusers.kspx page. The issue is triggered when a malicious user accesses the /dms/adminusers.kspx script directly. It is possible that the flaw may allow the malicious user the ability to read and change administrative options resulting in a loss of integrity. Secure the file with htaccess or something similar and upgrade to Keene Digital Media Server to 1.0.4 or newer. Also limit unwanted connections and communications with firewalling if possible. Approx. 30 minutes Yes Yes Yes High 3 7 8 5 8593 12272 Hacking Intern - Angriffe, Strategien, Abwehr, Marc Ruef, Marko Rogge, Uwe Velten and Wolfram Gieseke, November 1, 2002, Data Becker, Düsseldorf, ISBN 381582284X http://www.computec.ch