exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

telhack-shambala.txt

telhack-shambala.txt
Posted Jun 3, 2002
Authored by Daniel Nystrum

A directory traversal vulnerability found in Shambala v4.5 can lead to the disclosure of files that are stored outside the served directories. More info on this bug available here.

SHA-256 | 792ce8a4307b49251659094a08eb30bb916bc5d232a44e48c27fb7fa5360260f

telhack-shambala.txt

Change Mirror Download


Telhack 026 Inc. Security Advisory - #3
_________________________________________

Name: Shambala Server 4.5
Impact: Major (FTP Server vuln.), Medium (Web Server vuln.)
Date: June 30 / 2002
_________________________________________

Daniel Nyström a.k.a. excE <exce@netwinder.nu>

_I N F O_

Shambala Server is a personal Web/FTP server for Win 9*/NT.
When the web server is started it also starts the integrated
FTP server. There are are two previous issues that has been
disclosed on bugtraq by zillion in 2000 but he seem to have
missed these things.

Both of them: http://online.securityfocus.com/archive/1/138501

Vendor is at: http://www.evolvable.com , and yes, they were notified,
see bottom.

_P R O B L E M_

The integrated FTP server is vulnerable to a directory traversal
attack, that enables attackers to view the entire directory
structure and also download any file in it. There are also a
DoS condition present in the web server.

_I M P A C T_

An authenticated user may view any directory and/or download
any file on the system. An authenticated user may use this
to download the !_cleartext_! password file that lies one ..
below the web root.

I have also found a DoS condition in the Web server that
generates "Run-time error'5': Invalid procedure call or argument"
and crashes the server.

According to www.download.com, the program has been downloaded
57,957 times and 40 times last week. So it seems like this program
is still at use.

_E X P L O I T I N G_

Directory traversal / get any file
----------------------------------
ftp> ls ../../../ - and so on...
ftp> get ../../../ - and so on...

DoS condition in the Web server
-------------------------------
you# telnet 192.168.0.11 80
Trying 192.168.0.11...
Connected to 192.168.0.11.
Escape character is '^]'.
GET !"#¤%&/()=?
Connection closed by foreign host.
you#

_F I X E S_

Spent almost 20 minutes digging in the evolvable.com website for
an e-mail adress to contact them by, but none found. So I ended
up taking the e-mail adress from another (2 year old) advisory.
Still no reply. So the fix for now is: Uninstall Shambala.

/Daniel Nyström a.k.a. excE @ Telhack 026 Inc.

http://www.swesec.tk
http://www.telhack.tk
Login or Register to add favorites

File Archive:

July 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    27 Files
  • 2
    Jul 2nd
    10 Files
  • 3
    Jul 3rd
    35 Files
  • 4
    Jul 4th
    27 Files
  • 5
    Jul 5th
    18 Files
  • 6
    Jul 6th
    0 Files
  • 7
    Jul 7th
    0 Files
  • 8
    Jul 8th
    28 Files
  • 9
    Jul 9th
    44 Files
  • 10
    Jul 10th
    24 Files
  • 11
    Jul 11th
    25 Files
  • 12
    Jul 12th
    11 Files
  • 13
    Jul 13th
    0 Files
  • 14
    Jul 14th
    0 Files
  • 15
    Jul 15th
    0 Files
  • 16
    Jul 16th
    0 Files
  • 17
    Jul 17th
    0 Files
  • 18
    Jul 18th
    0 Files
  • 19
    Jul 19th
    0 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    0 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close