Microsoft IE5 WPAD Spoofing Vulnerability
BID:846
Info
Microsoft IE5 WPAD Spoofing Vulnerability
| Bugtraq ID: | 846 |
| Class: | Atomicity Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 02 1999 12:00AM |
| Updated: | Dec 02 1999 12:00AM |
| Credit: | Discovered by Tim Adam of Open Software Associates. Publicized in Microsoft Security Bulletin MS99-054, released on December 1, 1999. |
| Vulnerable: |
Microsoft Internet Explorer 5.0 for Windows NT 4 Microsoft Internet Explorer 5.0 for Windows 98 Microsoft Internet Explorer 5.0 for Windows 95 Microsoft Internet Explorer 5.0 for Windows 2000 |
| Not Vulnerable: |
Microsoft Internet Explorer 5.0.1 |
Discussion
Microsoft IE5 WPAD Spoofing Vulnerability
IE5's automatic proxy configuration feature, WPAD, (Web Proxy Auto-Discovery) can be fooled into using or attempting to use a non-authorized server as a proxy server. An attacker on a different network could use this to read web traffic from the IE5 client.
IE5 will search for a WPAD server by looking for machines named wpad.x.x.x in the current domain. If none is found, it will proceed up the domain name structure, until it gets to the third-level domain name.
For example, IE5 running on host a.b.c.d.net would first look for wpad.b.c.d.net, then wpad.c.d.net, then wpad.d.net.
In certain network configurations, the third-level domain is not neccessarily a trusted part of the network, and an attacker could set up a server to cause IE5 clients to use a hostile machine as proxy.
IE5's automatic proxy configuration feature, WPAD, (Web Proxy Auto-Discovery) can be fooled into using or attempting to use a non-authorized server as a proxy server. An attacker on a different network could use this to read web traffic from the IE5 client.
IE5 will search for a WPAD server by looking for machines named wpad.x.x.x in the current domain. If none is found, it will proceed up the domain name structure, until it gets to the third-level domain name.
For example, IE5 running on host a.b.c.d.net would first look for wpad.b.c.d.net, then wpad.c.d.net, then wpad.d.net.
In certain network configurations, the third-level domain is not neccessarily a trusted part of the network, and an attacker could set up a server to cause IE5 clients to use a hostile machine as proxy.
Exploit / POC
Microsoft IE5 WPAD Spoofing Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft IE5 WPAD Spoofing Vulnerability
Solution:
Microsoft has released the following patches which rectifies this issue:
http://www.microsoft.com/windows/ie/download/critical/patch6.htm
Solution:
Microsoft has released the following patches which rectifies this issue:
http://www.microsoft.com/windows/ie/download/critical/patch6.htm
References
Microsoft IE5 WPAD Spoofing Vulnerability
References:
References:
- Frequently Asked Questions: Microsoft Security Bulletin (MS00-033) (Microsoft)
- Frequently Asked Questions: Microsoft Security Bulletin MS99-054 (Microsoft)
- Web Proxy Auto-Discovery Protocol Internet Draft (Internet Engineering Task Force)