[12732] in bugtraq

home help back first fref pref prev next nref lref last post

Oracle Web Listener

daemon@ATHENA.MIT.EDU (Mnemonix)
Fri Nov 26 02:16:47 1999

Mime-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: 7bit
Message-Id:  <001001bf378e$68def870$0a01010a@cerberusinfosec.co.uk>
Date:         Thu, 25 Nov 1999 21:45:35 -0000
Reply-To: Mnemonix <mnemonix@GLOBALNET.CO.UK>
From: Mnemonix <mnemonix@GLOBALNET.CO.UK>
X-To:         BUGTRAQ@SECURITYFOCUS.COM, ntbugtraq@listserv.ntbugtraq.com
To: BUGTRAQ@SECURITYFOCUS.COM

There is a problem (seems to be a bug) with Oracle Web Listener where a
resource can be accessed when is shouldn't be able to be accessed:

Consider the following setup:
Access to  http://host/ows-bin/owa/thenormal.app _is_ allowed.

However access to the owa_util package in the same dir is not allowed so
requesting http://host/ows-bin/owa/owa_util.signature causes the Oracle Web
Listener to throw back an HTTP 401 response ie it requires a user id and
password. However by making a request and substituting the _ with %5f (eg.
http://host/ows-bin/owa/owa%5futil.signature)  we're granted access. Or
using %2e instead of the dot (eg.
http://host/ows-bin/owa/owa_util%2esignature ) does the same: we're given
access, then too.

On sites that protect access to owa_util using this method will be at great
risk from queries using showsource, cellsprint, tableprint and listprint.

Version Oracle_Web_listener2.1/1.20in2 on Solaris was tested. More recent
and earlier versions may also be affected but that's not known yet. Anybody
with access to such versions it - could you check?

TIA
Cheers,
David Litchfield
http://www.infowar.co.uk/mnemonix/
Cerberus Information Security

home help back first fref pref prev next nref lref last post