exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

aoljournals_advisory.txt

aoljournals_advisory.txt
Posted Oct 27, 2004
Authored by Steven

An information disclosure flaw in AOL Journals allows any remote attacker to increment BlogIDs in order to reveal other user email addresses.

tags | advisory, remote, info disclosure
SHA-256 | 02d5f5dd347c2ac7772bcb3d661d9a6de4bf662b8460563f0fcc4e1d311b4c14

aoljournals_advisory.txt

Change Mirror Download
Date:          October 22, 2004
Vendor: America Online Inc.
Issue: AOL Journals BlogID incrementing discloses account names and
e-mail addresses
URL: http://journals.aol.com / AOL Keyword: Journals
Advisory: http://www.lovebug.org/aoljournals_advisory.txt


Service Overview:

AOL Journals is basically America Online's version of a blog (weblog) for
AOL members/subscribers (excludes AIM users). It allows them to post
messages by logging into the service or by sending an instant message to the
screen name "AOL Journals"

Issue:

The issue lies within the Atom/RSS feed option for users. There is a link
on the journals that would allow users to get an Atom or RSS feed for that
weblog. The webpage that pops up containing these links to the feeds
displays the full path to the user's feed (which includes their username,
which is subsequently their e-mail address). The link to the feeds,
however, does not use the username in conjunction with the blog name.
Instead it uses a BlogID number which appears to just be incremented as
blogs are created.

As a result an attacker could increment through the numbers and obtain
thousands of user e-mail addresses. This flaw is especially noteworthy due
to the easy and speed at which an attacker could obtain the usernames.
Also, the username and blog names could be easily traversed through to gain
information on the user that could be used in conjunction with targeted spam
among other things.

Here is an example of the URL:

http://journals.aol.com/_do/rss_popup?blogID=#

Obviously replace # with a number. The current/newest ID# is in excess of
700000. Some numbers will return an error (they no longer exist) or they
will be for the same username. If a user chooses to create a new blog it
will start a new BlogID.

Solutions:

Don't tie the BlogID feed into the Atom/RSS feeds.

Vendor Response:

As mentioned in previous advisories related to America Online, there has
been no report to the vendor. All previous attempts to report bugs in
America Online have gone ignored. They also do not provide a point of
contact for reporting bugs. However, all contact with others employees at
America Online in related departments has yielded negative or no response.

Once again, if America Online would like to provide a point of contact for
bugs, I would gladly contact them prior to disclosure. E-mail:
steven@lovebug.org | Yes, there are currently more 'known' bugs.

Credits:

welcome.wav & gotmail.wav

Go Hokies! :D


-Steven
steven@lovebug.org


Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    0 Files
  • 11
    Sep 11th
    0 Files
  • 12
    Sep 12th
    0 Files
  • 13
    Sep 13th
    0 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    0 Files
  • 17
    Sep 17th
    0 Files
  • 18
    Sep 18th
    0 Files
  • 19
    Sep 19th
    0 Files
  • 20
    Sep 20th
    0 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close