NT IIS Showcode ASP Vulnerability
BID:167
Info
NT IIS Showcode ASP Vulnerability
| Bugtraq ID: | 167 |
| Class: | Access Validation Error |
| CVE: |
CVE-1999-0736 |
| Remote: | Yes |
| Local: | No |
| Published: | May 07 1999 12:00AM |
| Updated: | Jul 11 2009 12:16AM |
| Credit: | This vulnerability was discovered by Parcens. The vulnerability was made public by L0pht. Similar vulnerabilities where reported by Andrey Kruchkov and WebTrends. |
| Vulnerable: |
Microsoft Site Server Commerce Edition 3.0 SP2 i386 Microsoft Site Server Commerce Edition 3.0 SP2 alpha Microsoft Site Server Commerce Edition 3.0 SP1 i386 Microsoft Site Server Commerce Edition 3.0 SP1 alpha Microsoft Site Server Commerce Edition 3.0 i386 Microsoft Site Server Commerce Edition 3.0 alpha Microsoft Site Server 3.0 SP2 i386 Microsoft Site Server 3.0 SP2 alpha Microsoft Site Server 3.0 SP1 i386 Microsoft Site Server 3.0 SP1 alpha Microsoft Site Server 3.0 i386 Microsoft Site Server 3.0 alpha Microsoft IIS 4.0 alpha Microsoft IIS 4.0 |
| Not Vulnerable: |
Microsoft Site Server Commerce Edition 3.0 SP4 i386 Microsoft Site Server Commerce Edition 3.0 SP4 alpha Microsoft Site Server Commerce Edition 3.0 SP3 i386 Microsoft Site Server Commerce Edition 3.0 SP3 alpha Microsoft Site Server 3.0 SP4 i386 Microsoft Site Server 3.0 SP4 alpha Microsoft Site Server 3.0 SP3 i386 Microsoft Site Server 3.0 SP3 alpha |
Discussion
NT IIS Showcode ASP Vulnerability
A sample Active Server Page (ASP) script installed by default on Microsoft's Internet Information Server (IIS) 4.0 gives remote users access to view any file on the same volume as the web server that is readable by the web server.
IIS 4.0 installs a number of sample ASP scripts including one called "showcode.asp". This script allows clients to view the source of other sample scripts via a browser. The "showcode.asp" script does not perform sufficent checks and allows files outside the sample directory to be requested. In particular, it does not check for ".." in the path of the requested file.
The script takes one parameter, "source", which is the file to view. The script's default location URL is:
http://www.sitename.com/msadc/Samples/SELECTOR/showcode.asp
Similar vulnerabilities have been noted in ViewCode.asp, CodeBrws.asp and Winmsdp.exe.
A sample Active Server Page (ASP) script installed by default on Microsoft's Internet Information Server (IIS) 4.0 gives remote users access to view any file on the same volume as the web server that is readable by the web server.
IIS 4.0 installs a number of sample ASP scripts including one called "showcode.asp". This script allows clients to view the source of other sample scripts via a browser. The "showcode.asp" script does not perform sufficent checks and allows files outside the sample directory to be requested. In particular, it does not check for ".." in the path of the requested file.
The script takes one parameter, "source", which is the file to view. The script's default location URL is:
http://www.sitename.com/msadc/Samples/SELECTOR/showcode.asp
Similar vulnerabilities have been noted in ViewCode.asp, CodeBrws.asp and Winmsdp.exe.
Exploit / POC
NT IIS Showcode ASP Vulnerability
http://www.sitename.com/msadc/Samples/SELECTOR/showcode.asp?source=/msadc/Samples/../../../../../boot.ini
Using CodeBrws.asp, it is possible to view Outlook mail folders: http://some-sitename-here/iissamples/exair/howitworks/codebrws.asp?source=/../../winnt/Profiles/Administrator/Application%20Data/Microsoft/Outlook%20Express/Mail/inbox.mbx
http://www.sitename.com/msadc/Samples/SELECTOR/showcode.asp?source=/msadc/Samples/../../../../../boot.ini
Using CodeBrws.asp, it is possible to view Outlook mail folders: http://some-sitename-here/iissamples/exair/howitworks/codebrws.asp?source=/../../winnt/Profiles/Administrator/Application%20Data/Microsoft/Outlook%20Express/Mail/inbox.mbx
Solution / Fix
NT IIS Showcode ASP Vulnerability
Solution:
Do not install the sample code on production servers. If you have installed the sample code remove it or install the patches:
Microsoft Site Server 3.0 alpha
Microsoft Site Server Commerce Edition 3.0 SP2 i386
Microsoft Site Server Commerce Edition 3.0 SP2 alpha
Microsoft IIS 4.0 alpha
Microsoft Site Server 3.0 SP1 alpha
Microsoft Site Server 3.0 SP2 alpha
Microsoft IIS 4.0
Microsoft Site Server Commerce Edition 3.0 SP1 alpha
Microsoft Site Server 3.0 SP1 i386
Microsoft Site Server 3.0 i386
Microsoft Site Server Commerce Edition 3.0 i386
Microsoft Site Server 3.0 SP2 i386
Microsoft Site Server Commerce Edition 3.0 SP1 i386
Microsoft Site Server Commerce Edition 3.0 alpha
Solution:
Do not install the sample code on production servers. If you have installed the sample code remove it or install the patches:
Microsoft Site Server 3.0 alpha
-
Microsoft Site Server 3.0 Service Pack 4 (Alpha)
http://download.microsoft.com/download/siteserver30/SP/sp4/NT45/EN-US/ ss3sp4-alpha.EXE
Microsoft Site Server Commerce Edition 3.0 SP2 i386
-
Microsoft Site Server 3.0 Service Pack 4 (Alpha)
http://download.microsoft.com/download/siteserver30/SP/sp4/NT45/EN-US/ ss3sp4-alpha.EXE -
Microsoft Site Server 3.0 Service Pack 4 (Intel)
http://download.microsoft.com/download/siteserver30/SP/sp4/NT45/EN-US/ ss3sp4-x86.EXE
Microsoft Site Server Commerce Edition 3.0 SP2 alpha
-
Microsoft Site Server 3.0 Service Pack 4 (Alpha)
http://download.microsoft.com/download/siteserver30/SP/sp4/NT45/EN-US/ ss3sp4-alpha.EXE
Microsoft IIS 4.0 alpha
-
Microsoft fix2450a
ftp://ftp.microsoft.com/bussys/iis/iis-public/fixes/usa/Viewcode-fix/f ix2450a.exe
Microsoft Site Server 3.0 SP1 alpha
-
Microsoft Site Server 3.0 Service Pack 4 (Alpha)
http://download.microsoft.com/download/siteserver30/SP/sp4/NT45/EN-US/ ss3sp4-alpha.EXE
Microsoft Site Server 3.0 SP2 alpha
-
Microsoft Site Server 3.0 Service Pack 4 (Alpha)
http://download.microsoft.com/download/siteserver30/SP/sp4/NT45/EN-US/ ss3sp4-alpha.EXE
Microsoft IIS 4.0
-
Microsoft fix2450i
ftp://ftp.microsoft.com/bussys/iis/iis-public/fixes/usa/viewcode-fix/f ix2450i.exe
Microsoft Site Server Commerce Edition 3.0 SP1 alpha
-
Microsoft Site Server 3.0 Service Pack 4 (Alpha)
http://download.microsoft.com/download/siteserver30/SP/sp4/NT45/EN-US/ ss3sp4-alpha.EXE
Microsoft Site Server 3.0 SP1 i386
-
Microsoft Site Server 3.0 Service Pack 4 (Alpha)
http://download.microsoft.com/download/siteserver30/SP/sp4/NT45/EN-US/ ss3sp4-alpha.EXE -
Microsoft Site Server 3.0 Service Pack 4 (Intel)
http://download.microsoft.com/download/siteserver30/SP/sp4/NT45/EN-US/ ss3sp4-x86.EXE
Microsoft Site Server 3.0 i386
-
Microsoft Site Server 3.0 Service Pack 4 (Alpha)
http://download.microsoft.com/download/siteserver30/SP/sp4/NT45/EN-US/ ss3sp4-alpha.EXE -
Microsoft Site Server 3.0 Service Pack 4 (Intel)
http://download.microsoft.com/download/siteserver30/SP/sp4/NT45/EN-US/ ss3sp4-x86.EXE
Microsoft Site Server Commerce Edition 3.0 i386
-
Microsoft Site Server 3.0 Service Pack 4 (Alpha)
http://download.microsoft.com/download/siteserver30/SP/sp4/NT45/EN-US/ ss3sp4-alpha.EXE -
Microsoft Site Server 3.0 Service Pack 4 (Intel)
http://download.microsoft.com/download/siteserver30/SP/sp4/NT45/EN-US/ ss3sp4-x86.EXE
Microsoft Site Server 3.0 SP2 i386
-
Microsoft Site Server 3.0 Service Pack 4 (Alpha)
http://download.microsoft.com/download/siteserver30/SP/sp4/NT45/EN-US/ ss3sp4-alpha.EXE -
Microsoft Site Server 3.0 Service Pack 4 (Intel)
http://download.microsoft.com/download/siteserver30/SP/sp4/NT45/EN-US/ ss3sp4-x86.EXE
Microsoft Site Server Commerce Edition 3.0 SP1 i386
-
Microsoft Site Server 3.0 Service Pack 4 (Alpha)
http://download.microsoft.com/download/siteserver30/SP/sp4/NT45/EN-US/ ss3sp4-alpha.EXE -
Microsoft Site Server 3.0 Service Pack 4 (Intel)
http://download.microsoft.com/download/siteserver30/SP/sp4/NT45/EN-US/ ss3sp4-x86.EXE
Microsoft Site Server Commerce Edition 3.0 alpha
-
Microsoft Site Server 3.0 Service Pack 4 (Alpha)
http://download.microsoft.com/download/siteserver30/SP/sp4/NT45/EN-US/ ss3sp4-alpha.EXE -
Microsoft Site Server 3.0 Service Pack 4 (Intel)
http://download.microsoft.com/download/siteserver30/SP/sp4/NT45/EN-US/ ss3sp4-x86.EXE
References
NT IIS Showcode ASP Vulnerability
References:
References:
- Q231368: Solution Available for File Viewers Vulnerability (Microsoft)
- Q231656: Preventing ViewCode.asp from Viewing Known Server Files (Microsoft)
- Viewing Files with IIS (NTSecurity)