what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

flickstitan.txt

flickstitan.txt
Posted Nov 22, 2001

The Flicks Titan application firewall for IIS has a vulnerability in the url inspection allowing it to be easily bypassed.

tags | exploit
SHA-256 | c9ae3c7cec218aa4c0a512ca5aab4dada76da541b52fcc647bd0702fc4ea36a6

flickstitan.txt

Change Mirror Download
I originally sent this message to bugtraq, but they did not post 
it. Instead they stuck it in their vulnerability database and
removed all of my comments and example. So much for full disclosure...

Flicks Software just released a product named Titan[1]. It is
described as an application firewall (i.e., it is an ISAPI filter for
IIS that can do varying levels of protocol inspection). One of the
features allows a user to filter on patterns within the URL for things
such as cmd.exe.

The problem is the guys at Flicks obviously don't understand web
security (which is scary because they have been developing AuthentiX
for some time now, not to mention the version of Titan I had was 5.5a7,
I am baffled at how a 5th major revision piece of software can be so
fundamentally broken).

I started off by placing cmd.exe into an executeable folder on my
web server and enabling the Titan security. As expected, I received
an error message when attempting to access the file. I then proceeded
to try a trick my little sister showed me. I URL encoded some of
the characters in the URL like so:

http://www.example.com/scripts/cmd%2Eexe?/C+dir+c:%5C

Would you believe that I got a directory listing back? I did.

What further disturbs me is that this has already been done, by
Microsoft and their arch rivals -- eEye[2]. eEye was first to market
with their SecureIIS product (~$400). I suspect that M$ then
released URLScan[3] for free as a jab at all the M$ advisories eEye
releases. So there are two decent products out there and Flicks
releases this piece of JUNK and thinks they can get ~$400 a pop.
HA! What a joke.


[1] http://www.flicks.com/titan
[2] http://www.eeye.com
[3] http://www.google.com?q=urlscan

Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close