exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

netegrity.txt

netegrity.txt
Posted Jan 19, 2005
Authored by Marc Ruef | Site computec.ch

The Netegrity SiteMinder smpwservicescgi.exe is susceptible to a remote data inclusion vulnerability that allows for phishing attacks.

tags | exploit, remote
SHA-256 | ba2e8bce8ac6c15f997f1dbeffe9a186f5050292a7ea62b8f9c7ae2dde132eee

netegrity.txt

Change Mirror Download
 
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Dear ladies and gentlemen

We have found a potential security vulnerability in the Netegrity SiteMinder script smpwservicescgi.exe. If a user is connecting to a secured web server over an url like https://www.scip.ch (just an example with our domain) he will get forwarded to the logon url https://www.scip.ch/siteminderagent/pwcgi/smpwservicescgi.exe?TYPE=32564432&REALMOID=02-0005b182-32f3-2121-ab24-8350cdfdaf3b&GUID=&SMAUTHREASON=0&METHOD=GET&SMAGENTNAME=$SM$5rR6TLmkLOjh8Qac1FGeB5OHEA63VfWpQjt0OYda1BBrydPC0NKSWg%3d%3d&TARGET=$SM$https%3a%2f%2fwww%2escip%2ech%2fintern%2ehtml - In this url string several data is prepared to be processed as $QUERY_STRING in a common form http get request. As you can see, the last variant is named TARGET. This specifies the target url after authentication. In the example the url https://www.scip.ch/internal.html

The problem is, that a malicous user may use this to realize a social hacking or phishing attack. He may define a malicous web site as target to forward to another web site with unrelated content (e.g. porn), a cross site scripting or more severe vulnerability (e.g. JPEG exploit). The lack of reputation or launching another attack may be possible. It is also possible to shorten the malicous url to https://www.scip.ch/siteminderagent/pwcgi/smpwservicescgi.exe?TARGET=http%3a%2f%2fwww%2ecomputec%2ech - This is ideal to put it into a phishing mail. You find the original advisory, written in german, on http://www.scip.ch/cgi-bin/smss/showadvf.pl?id=1022 (Netegrity SiteMinder Login TARGET-Weiterleitung Designfehler).

We have not found any information on that issue. So I sent this information (nearly the same posting) on 14/12/04 to info-emea@netegrity.com and asked for a solution. As I haven't heard _anything_ until 23/12/04 I sent a reminder email. Due no reply came back we made this vulnerability public finally to force Netegrity to react on this case. An Attack Tool Kit (ATK) plugin that addresses this vulnerability will be published in the next days[1].

Regards,

Marc Ruef

[1] http://www.computec.ch/projekte/atk/

- --
) scip AG (
Technoparkstr. 1
8005 Zürich
T +41 1 445 18 18
F +41 1 445 18 19

maru@scip.ch
www.scip.ch

- - Aktuellste IT-Sicherheitsluecken -

-----BEGIN PGP SIGNATURE-----
Version: PGP 8.0
Comment: http://www.scip.ch

iQA/AwUBQevrDhe5hzJzqVMhEQLX8QCeNnfaNUTqAlkNqF49dV/jyTFwuBoAn3UG
KAjYMXWByPzqHfyzGxw7dlHw
=eo/G
-----END PGP SIGNATURE-----
Login or Register to add favorites

File Archive:

December 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Dec 1st
    0 Files
  • 2
    Dec 2nd
    41 Files
  • 3
    Dec 3rd
    0 Files
  • 4
    Dec 4th
    0 Files
  • 5
    Dec 5th
    0 Files
  • 6
    Dec 6th
    0 Files
  • 7
    Dec 7th
    0 Files
  • 8
    Dec 8th
    0 Files
  • 9
    Dec 9th
    0 Files
  • 10
    Dec 10th
    0 Files
  • 11
    Dec 11th
    0 Files
  • 12
    Dec 12th
    0 Files
  • 13
    Dec 13th
    0 Files
  • 14
    Dec 14th
    0 Files
  • 15
    Dec 15th
    0 Files
  • 16
    Dec 16th
    0 Files
  • 17
    Dec 17th
    0 Files
  • 18
    Dec 18th
    0 Files
  • 19
    Dec 19th
    0 Files
  • 20
    Dec 20th
    0 Files
  • 21
    Dec 21st
    0 Files
  • 22
    Dec 22nd
    0 Files
  • 23
    Dec 23rd
    0 Files
  • 24
    Dec 24th
    0 Files
  • 25
    Dec 25th
    0 Files
  • 26
    Dec 26th
    0 Files
  • 27
    Dec 27th
    0 Files
  • 28
    Dec 28th
    0 Files
  • 29
    Dec 29th
    0 Files
  • 30
    Dec 30th
    0 Files
  • 31
    Dec 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close