Received: by taz.hyperreal.com (8.6.12/8.6.5) id SAA06840; Wed, 3 Jul 1996 18:17:39 -0700 Received: from sierra.zyzzyva.com by taz.hyperreal.com (8.6.12/8.6.5) with ESMTP id SAA06834; Wed, 3 Jul 1996 18:17:34 -0700 Received: from zyzzyva.com (localhost [127.0.0.1]) by sierra.zyzzyva.com (8.7.5/8.6.11) with ESMTP id UAA23534 for ; Wed, 3 Jul 1996 20:17:37 -0500 (CDT) Message-Id: <199607040117.UAA23534@sierra.zyzzyva.com> To: new-httpd@apache.org Subject: Security Interest Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Date: Wed, 03 Jul 1996 20:17:36 -0500 From: Randy Terbush Sender: owner-new-httpd@apache.org Precedence: bulk Reply-To: new-httpd@hyperreal.com ------- Forwarded Message Date: Wed, 3 Jul 1996 14:50:06 -0700 (PDT) From: TTT Group To: firewalls@GreatCircle.COM Subject: *** SECURITY ALERT *** I spent some time exploring Novell's HTTP server and out of the box there is a CGI that is VERY VERY INSECURE!!!!!!!!!!!!!!!!!!!!!!!!! !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! If you are running the Novell HTTP server, please disable the CGI's it comes with it until you understand (fully understand) what the security risks are. !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! The CGI in question is convert.bas (yes, cgi's in basic, stop laughing). (There may be more CGI's in the scripts dir that can be exploited but this was all I could stomoch.) A remote user can read any file on the remote file system using this CGI. This means that if you are running the Novell HTTP server and have the 'out of box' CGI's, you are breached. Exploit code: http://victim.com/scripts/convert.bas?../../anything/you/want/to/view I was going to see how bad this threat was by connecting to www servers, testing for "Novell HTTP" in the HTTP server responce BUT WHY DO THAT WHEN YOU HAVE www.altavista.digital.com :-) +links:scripts/convert.bas will return you all the sites that can be breached. PLEASE PLEASE PLEASE don't open the box and put machine on the Internet. I am getting tired of this kind of stuff. Who the hell did Novell consult with to write these darn CGI's? It makes me sad. --blast ------- End of Forwarded Message