AutoLog IP Spoofing Vulnerability
BID:4627
Info
AutoLog IP Spoofing Vulnerability
| Bugtraq ID: | 4627 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 29 2002 12:00AM |
| Updated: | Apr 29 2002 12:00AM |
| Credit: | Discovery of this issue is credited to frog frog <[email protected]>. |
| Vulnerable: |
BigB AutoLog 27/07/01 |
| Not Vulnerable: | |
Discussion
AutoLog IP Spoofing Vulnerability
AutoLog is website usage tracking software. It will run on most Unix and Linux variants, as well as Microsoft Windows operating systems.
By sending a specially crafted cookie containing an arbitrary IP address, a remote attacker may cause a false IP to be logged by the script.
AutoLog is website usage tracking software. It will run on most Unix and Linux variants, as well as Microsoft Windows operating systems.
By sending a specially crafted cookie containing an arbitrary IP address, a remote attacker may cause a false IP to be logged by the script.
Exploit / POC
AutoLog IP Spoofing Vulnerability
To exploit this issue the attacker submits a cookie containing a false IP address.
To exploit this issue the attacker submits a cookie containing a false IP address.
Solution / Fix
AutoLog IP Spoofing Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
AutoLog IP Spoofing Vulnerability
References:
References:
- AutoLog Homepage (BigB)
- Security holes in 11 products... (frog frog
)