Abyss Web Server Authentication Bypass Vulnerability
BID:9171
Info
Abyss Web Server Authentication Bypass Vulnerability
| Bugtraq ID: | 9171 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 08 2003 12:00AM |
| Updated: | Dec 08 2003 12:00AM |
| Credit: | The disclosure of this issue has been credited to Luigi Auriemma <[email protected]>. |
| Vulnerable: |
Aprelium Technologies Abyss Web Server 1.1.6 Beta Aprelium Technologies Abyss Web Server 1.1.4 Aprelium Technologies Abyss Web Server 1.1.2 Aprelium Technologies Abyss Web Server 1.0.7 Aprelium Technologies Abyss Web Server 1.0.3 Aprelium Technologies Abyss Web Server 1.0 |
| Not Vulnerable: |
Aprelium Technologies Abyss Web Server 1.2 |
Discussion
Abyss Web Server Authentication Bypass Vulnerability
It has been reported that Abyss Web Server is prone to an authentication bypass vulnerability that may allow an attacker to gain access to server resources. This issue may be carried out by accessing a password protected directory under which the server is running by adding a period as '.' or '%2e' at the end of a URL request. This problem only presents itself when the server is installed on a Linux system running FAT32.
Abyss Web Server versions prior to 1.2 have been reported prone to this issue.
It has been reported that Abyss Web Server is prone to an authentication bypass vulnerability that may allow an attacker to gain access to server resources. This issue may be carried out by accessing a password protected directory under which the server is running by adding a period as '.' or '%2e' at the end of a URL request. This problem only presents itself when the server is installed on a Linux system running FAT32.
Abyss Web Server versions prior to 1.2 have been reported prone to this issue.
Exploit / POC
Abyss Web Server Authentication Bypass Vulnerability
The following proof of concept examples have been provided:
http://www.example.com/protected_FAT32_dir.
http://www.example.com/protected_FAT32_dir./
http://www.example.com/protected_FAT32_dir%2e
The following proof of concept examples have been provided:
http://www.example.com/protected_FAT32_dir.
http://www.example.com/protected_FAT32_dir./
http://www.example.com/protected_FAT32_dir%2e
Solution / Fix
Abyss Web Server Authentication Bypass Vulnerability
Solution:
The vendor has released version 1.2 of the server to address this issue:
Aprelium Technologies Abyss Web Server 1.0
Aprelium Technologies Abyss Web Server 1.0.3
Aprelium Technologies Abyss Web Server 1.0.7
Aprelium Technologies Abyss Web Server 1.1.2
Aprelium Technologies Abyss Web Server 1.1.4
Aprelium Technologies Abyss Web Server 1.1.6 Beta
Solution:
The vendor has released version 1.2 of the server to address this issue:
Aprelium Technologies Abyss Web Server 1.0
-
Aprelium Technologies Abyss Web Server 1.2
http://www.aprelium.com/abyssws/download.php
Aprelium Technologies Abyss Web Server 1.0.3
-
Aprelium Technologies Abyss Web Server 1.2
http://www.aprelium.com/abyssws/download.php
Aprelium Technologies Abyss Web Server 1.0.7
-
Aprelium Technologies Abyss Web Server 1.2
http://www.aprelium.com/abyssws/download.php
Aprelium Technologies Abyss Web Server 1.1.2
-
Aprelium Technologies Abyss Web Server 1.2
http://www.aprelium.com/abyssws/download.php
Aprelium Technologies Abyss Web Server 1.1.4
-
Aprelium Technologies Abyss Web Server 1.2
http://www.aprelium.com/abyssws/download.php
Aprelium Technologies Abyss Web Server 1.1.6 Beta
-
Aprelium Technologies Abyss Web Server 1.2
http://www.aprelium.com/abyssws/download.php
References
Abyss Web Server Authentication Bypass Vulnerability
References:
References:
- Abyss Web Server Homepage (Aprelium Technologies)
- FAT32 directory auth bypass on Linux Abyssws < 1.2 (Luigi Auriemma
)