ServerMask Improper Header Anonymization Weakness
BID:10905
Info
ServerMask Improper Header Anonymization Weakness
| Bugtraq ID: | 10905 |
| Class: | Design Error |
| CVE: |
CVE-2003-0105 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 10 2004 12:00AM |
| Updated: | Jul 12 2009 06:16AM |
| Credit: | Martin O'Neal from Corsaire is credited for discovery of this weakness. |
| Vulnerable: |
Port80 ServerMask 2.2 Port80 ServerMask 2.1 Port80 ServerMask 2.0 Port80 ServerMask 1.2 Port80 ServerMask 1.1.1 Port80 ServerMask 1.1 .0 Port80 ServerMask 1.0 |
| Not Vulnerable: | |
Discussion
ServerMask Improper Header Anonymization Weakness
It is reported that ServerMask contains a weakness that allows servers to be identified as IIS, even when the product is functioning as advertised.
Unique traits of IIS servers are not properly filtered or altered in any way. This allows an attacker to remotely discern the type of web server, even in the presence of the ServerMask software.
ServerMask versions 2.2 and prior are reported to contain this weakness.
It is reported that ServerMask contains a weakness that allows servers to be identified as IIS, even when the product is functioning as advertised.
Unique traits of IIS servers are not properly filtered or altered in any way. This allows an attacker to remotely discern the type of web server, even in the presence of the ServerMask software.
ServerMask versions 2.2 and prior are reported to contain this weakness.
Exploit / POC
ServerMask Improper Header Anonymization Weakness
No exploit is required.
No exploit is required.
Solution / Fix
ServerMask Improper Header Anonymization Weakness
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
ServerMask Improper Header Anonymization Weakness
References:
References:
- ServerMask Home Page (Port80)
- Corsaire Security Advisory - Port80 Software ServerMask inconsistencies ("advisories"
)