183
Keene Digital Media Server prior 1.0.3 Adminsitrative Authentication Bypass
HTTP
2004/09/07
Nico 'Triplex' Spicher
Triplex at IT-Helpnet dot de
http://triplex.it-helpnet.de/
http://www.it-helpnet.de/
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
2004/11/13
1.2
Made some slight modifications in version 1.1. Corrected the plugin structure and added the accuracy values in 1.2
tcp
8080
open|send GET /dms/adminusers.kspx HTTP/1.0\n\n|sleep|close|pattern_exists 200
85
This plugin was written with the ATK-Plugin-Creator [http://triplex.it-helpnet.de].
Ziv Kamir
vulncode at yahoo dot com
2004/08/12
http://secunia.com/advisories/12272
Keene Digital Media Server 1.0.2 and 1.0.3
Keene Digital Media Server 1.0.4 and newer
Configuration
Keene Digital Media Server contains a flaw that may allow a malicious user to bypass authentication used to protect the adminusers.kspx page. The issue is triggered when a malicious user accesses the /dms/adminusers.kspx script directly. It is possible that the flaw may allow the malicious user the ability to read and change administrative options resulting in a loss of integrity.
Secure the file with htaccess or something similar and upgrade to Keene Digital Media Server to 1.0.4 or newer. Also limit unwanted connections and communications with firewalling if possible.
Approx. 30 minutes
Yes
Yes
Yes
High
3
7
8
5
8593
12272
Hacking Intern - Angriffe, Strategien, Abwehr, Marc Ruef, Marko Rogge, Uwe Velten and Wolfram Gieseke, November 1, 2002, Data Becker, Düsseldorf, ISBN 381582284X
http://www.computec.ch