[37668] in bugtraq
Re: Multiple Vulnerabilities in paFileDB 3.1
daemon@ATHENA.MIT.EDU (Rafael San Miguel Carrasco)
Thu Dec 9 17:13:04 2004
Message-ID: <41B8B363.8000605@yahoo.es>
Date: Thu, 09 Dec 2004 21:19:47 +0100
From: Rafael San Miguel Carrasco <smcsoc@yahoo.es>
MIME-Version: 1.0
To: bugtraq@securityfocus.com
In-Reply-To: <20041207072554.25718.qmail@www.securityfocus.com>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 8bit
I don't think this issue can be considered a vulnerability in paFileDB.
It's rather about Apache indexing the content of a web directory.
This is a misconfiguration issue in your httpd.conf.
Note that paFileDB is doing things right: it builds secure filenames
(since they cannot be guessed by trial-error in a reasonable amount of
time).
Hope this helps,
Rafael San Miguel Carrasco
>Scenario :
>
>* admin (dudul) log in to manage the site at
>http://URL/pafiledb/pafiledb.php?action=admin ,then the session is
recorded in
>sessions directory
>
>+ attacker access the directory directly and see the "sessions" (in a
same time)
>
>Exploit: http://URL/pafiledb/sessions/[sessionfile]
>
-------------------------------
Rafael San Miguel Carrasco
Consultor Técnico
rafael.sanmiguel@dvc.es
+ 34 660 856 647
+ 34 902 464 546
Davinci Consulting - www.dvc.es
Oficina Madrid - Parque empresarial Alvento
Via de los Poblados 1 Edificio A 6ª planta
28033 Madrid
-------------------------------