Zeus Webserver Possible Remote root Compromise
BID:742
Info
Zeus Webserver Possible Remote root Compromise
| Bugtraq ID: | 742 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 25 1999 12:00AM |
| Updated: | Oct 25 1999 12:00AM |
| Credit: | This was discovered and posted to BugTraq by rain forest puppy <[email protected]> on Oct 25, 1999. |
| Vulnerable: |
Zeus Technologies Zeus Web Server 3.3.2 Zeus Technologies Zeus Web Server 3.3.1 |
| Not Vulnerable: |
Zeus Technologies Zeus Web Server 3.1.9 Zeus Technologies Zeus Web Server 3.1.8 Zeus Technologies Zeus Web Server 3.1.7 Zeus Technologies Zeus Web Server 3.1.6 Zeus Technologies Zeus Web Server 3.1.5 Zeus Technologies Zeus Web Server 3.1.4 Zeus Technologies Zeus Web Server 3.1.3 Zeus Technologies Zeus Web Server 3.1.2 Zeus Technologies Zeus Web Server 3.1.1 Zeus Technologies Zeus Web Server 3.0.9 Zeus Technologies Zeus Web Server 3.0.8 Zeus Technologies Zeus Web Server 3.0.7 Zeus Technologies Zeus Web Server 3.0.6 Zeus Technologies Zeus Web Server 3.0.5 |
Discussion
Zeus Webserver Possible Remote root Compromise
There are a number of vulnerabilities in the Zeus Web Server, that if carried out in combination can lead to a remote root compromise.
The Zeus Web Server gives its users the option to use a pre-built search CGI program for their virtual website. The program accepts (as its http form variables) server filesystem paths as its arguments. Because of this, it is possible to display any file that the server has access to. Thus, by altering parameters to "search", an attacker can obtain the password hash for the admin user by displaying the configuration file.
Once a password for the admin user is cracked, it is possible to execute aribtrary commands through the web based configuration UI as root (which the configuration UI runs as).
There are a number of vulnerabilities in the Zeus Web Server, that if carried out in combination can lead to a remote root compromise.
The Zeus Web Server gives its users the option to use a pre-built search CGI program for their virtual website. The program accepts (as its http form variables) server filesystem paths as its arguments. Because of this, it is possible to display any file that the server has access to. Thus, by altering parameters to "search", an attacker can obtain the password hash for the admin user by displaying the configuration file.
Once a password for the admin user is cracked, it is possible to execute aribtrary commands through the web based configuration UI as root (which the configuration UI runs as).
Exploit / POC
Zeus Webserver Possible Remote root Compromise
See discussion.
See discussion.
Solution / Fix
Zeus Webserver Possible Remote root Compromise
Solution:
Zeus Technology has released new binaries for their webserver which are not vulnerable to this problem. They are available at the location below:
http://support.zeus.co.uk/news/exploit.html
Users who are upgrading from version 3.1.9 or earlier should follow the upgrade steps at the following URL:
http://support.zeus.co.uk/faq/entries/z33migrate.html
It should be noted that Zeus responded to and fixed this problem within 3 hours of it being posted to BugTraq/on Security Focus.
Solution:
Zeus Technology has released new binaries for their webserver which are not vulnerable to this problem. They are available at the location below:
http://support.zeus.co.uk/news/exploit.html
Users who are upgrading from version 3.1.9 or earlier should follow the upgrade steps at the following URL:
http://support.zeus.co.uk/faq/entries/z33migrate.html
It should be noted that Zeus responded to and fixed this problem within 3 hours of it being posted to BugTraq/on Security Focus.
References
Zeus Webserver Possible Remote root Compromise
References:
References:
- Zeus Technology Homepage (Zeus Technology)