RE: [Fwd: Vulnerabilities in Informix Webdriver]
Answered: amber (hollow confidence) — Forwarded Informix Webdriver vulnerability report; heidi attributes the reported behaviour to misconfiguration (default admin page + tracing left on) and Paul Watson agrees it's user error rather than a real vulnerability, but the original reporter never weighs in and the 'question' itself is only implicit.
Advisory only.
Posted in 2001
Topics: Stored Procedures & SPL, Server Administration, Platform-Specific Issues
He may have configured his Web DataBlade Administrtion Tool to display the APB Main Menu first or as the default page. Also he should reconfigure the webdriver tracing. heidi > -----Original Message----- > From: owner-informix-list@iiug.iiug.org > [mailto:owner-informix-list@iiug.iiug.org]On Behalf Of Paul Watson > Sent: Wednesday, January 03, 2001 06:03 > To: informix-list@iiug.org > Subject: Re: [Fwd: Vulnerabilities in Informix Webdriver] > > > Which versions? and what webserver? > > Apache 1.3.12/WebDriver4.00.UC1 under Solaris 2.7 is OK, or appears to > be. > > Brett Geer wrote: > > > > Anyone know anything about this? from the BUGTRAQ list > > > > brett > > > > isno wrote: > > > > > > Webdriver is the web interface of Informix database,I found it is > > > vulnerable.In the common condition,webdriver is submitted with a > > > parameter,but if you type http://victim/cgi-bin/webdriver directly, It > > > will return a webpage which you can modify or delete database on it. > > > > > > Otherwise, webdriver will make a /tmp/.log file,its attribute is > > > -rw-rw-rw,we can make a symlink and get the nobody privilege,although > > > without root privilege,we can deface the website as nobody. > > > > > > > > > > > > isno(isno@etang.com) > > > > > > > -- > > > > ----------------------------------------------------------------- > > Brett's 10th law of UNIX administration... > > rm is forever > > ----------------------------------------------------------------- > > Brett Geer - UNIX Admin/Analyst/Programmer - Intratex Holdings. > > Tel. +27 31 717 4000 Direct. +27 31 717 4146 > > Fax. +27 31 717 4001 > > ----------------------------------------------------------------- > > The little voices are talking to me again, telling me to reach > > for a keyboard and type rm -rf /* > > last week they had me rm -rf `echo $MANPATH | sed 's/:/ /g'` > > now I fear I have no answers > > ----------------------------------------------------------------- > > -- > Paul Watson # > Oninit Ltd # You are only young once > Tel: +44 1436 672201 # but you can be immature > Fax: +44 1436 678693 # for ever > www.oninit.com # >
heidi wrote: > > He may have configured his Web DataBlade Administrtion Tool to display the > APB Main Menu first or as the default page. That's not a vulnerability, it's stupidity > Also he should reconfigure the webdriver tracing. -- Paul Watson # Oninit Ltd # You are only young once Tel: +44 1436 672201 # but you can be immature Fax: +44 1436 678693 # for ever www.oninit.com #
In the year of Our Lord Fri, 05 Jan 2001 19:30:40 +0000, Paul Watson <paul@oninit.com> broke a vow of silence to utter: >heidi wrote: >> >> He may have configured his Web DataBlade Administrtion Tool to display the >> APB Main Menu first or as the default page. > >That's not a vulnerability, it's stupidity Don't hold back now, Paul -- tell us exactly how you feel!