[20598] in bugtraq

home help back first fref pref prev next nref lref last post

[eyeonsecurity.net] Incredimail allows automatic over writing

daemon@ATHENA.MIT.EDU (Obscure -)
Mon May 14 03:32:44 2001

Message-ID: <20010511171537.5975.qmail@cybergoth.i-p.com>
Content-Type: text/plain; charset="iso-8859-1"
Content-Disposition: inline
Content-Transfer-Encoding: 7bit
Mime-Version: 1.0
From: "Obscure -" <obscure@cybergoth.i-p.com>
To: bugtraq@securityfocus.com
Date: Fri, 11 May 2001 18:15:37 +0100

Advisory Title: Incredimail allows automatic over writing of files on your hard disk 

Release Date: 05/08/2001


Application: Incredimail


Platform: Windows NT4
Windows 2000
Windows 9x/me


Build: 1400185 .. possibly earlier builds as well


Severity: Malicious users can easily over write system files.


Author: Obscure^ [obscure@cybergoth.i-p.com]


Vendor Status: Did not respond to my e-mails. Maybe not interested, or asleep (?) ...


Web: 

http://irc.m0ss.com/eos/main.pl?main=advisories/incredimail.html&menu=menu/advisories.html (maybe wrapped)
http://www.incredimail.com 



Background.

(extracted from 
http://www.incredimail.com/english/what.html)

IncrediMail is an advanced email program that offers you, 
the user, an unprecedented interactive experience. With 
IncrediMail you can tailor your emails according to your 
mood and personality. Visual effects will entertain your 
every sense. Go ahead. Express yourself like you never 
did before!

My comments: Incredimail does really look quite cool, with 
animations similar to the e-mail on Mission Impossible,
plus it's free.


Problem.

Users can specify the filename of the skin, notifyer, animation etc
This is specified in a text file called Content.ini, which is 
found in the compressed skin or animation. 
By appending the traditional dot dot to the filename, malicious users 
can easily over write any files on the same partition as Incredimail 
is intalled to.
The file is automatically downloaded and copied to the client 
machine when it accesses a site or e-mail which starts a download 
for the Incredimail file. If the file already exists it tries
to over write it.

See the exploit example.


Exploit Example.

http://irc.m0ss.com/eos/advisories/incredimailexploit
This webpage will simply create a file on C: (depends on which
partition you installed Incredimail) named Obscure.dat.



Disclaimer.

The information within this document may change without notice. Use of
this information constitutes acceptance for use in an AS IS
condition. There are NO warranties with regard to this information.
In no event shall the author be liable for any consequences whatsoever
arising out of or in connection with the use or spread of this
information. Any use of this information lays within the user's
responsibility.


Feedback.

Please send suggestions, updates, and comments to:

Eye on Security
mail:obscure@cybergoth.i-p.com
http://irc.m0ss.com/eos
-- 
[ Free e-mail @ http://www.cybergoth.cjb.net ]





Powered by Instant Portal

home help back first fref pref prev next nref lref last post