the internet's safety

ContentKeeper-123.25.txt

ContentKeeper-123.25.txt
Posted Oct 2, 2006
Authored by Patrick Webster | Site aushack.com

ContentKeeper 123.25 and below suffers from a design flaw in the user administration interface which reveals account passwords inside the HTML source code. Any authenticated user with appropriate access to the user administration page may use this information to compromise the accounts on other systems.

tags | advisory
MD5 | 8d21025d439de1c8b81c2f2abe5480a9

ContentKeeper-123.25.txt

Change Mirror Download
aushack.com - Vulnerability Advisory
-----------------------------------------------
Release Date:
22-Sep-2006

Software:
ContentKeeper Technologies - ContentKeeper
http://www.contentkeeper.com/

"ContentKeeper is an industry leading Internet content filter that allows
organisations to monitor, manage, control & secure staff access to
Internet resources."

Versions affected:
ContentKeeper 123.25 and below.

Vulnerability discovered:

A design flaw in the user administration interface reveals account
passwords inside the HTML source code. Any authenticated user with
appropriate access to the user administration page may use this
information to compromise the accounts on other systems.

Vulnerability impact:

Low - Unauthorised password disclosure may result in other system account
breaches where the revealed password has been reused.

Vulnerability information

The appliance is administered by use of a web browser HTML based front
end. Authenticated users have access to the account administration page,
whereby they can administer existing usernames, reset passwords, create
and delete accounts etc. The appliance does not hash the existing user
passwords. When the page is requested, the plaintext password for each
account is inserted into the password input value of the FORM element
and sent to the client.

Example:
https://contentkeeperbox/cgi-bin/ck/changepw.cgi

This will return all user details. By viewing the page source,
the password of each account is revealed.

E.g. for user 'root' with a password of 'it_isAs3cret':

<form>
<input name="username" type="text" value="root">Username:
<input type="password" name="password" value="it_isAs3cret">Password:
..
<input name="username" type="text" value="rootBackup">Username:
<input type="password" name="password" value="IamF0rgetful">Password:
</form>

It may be possible to extract this information from the browser cache,
however the HTML content is set to expire immediately.

Solution:
None yet, do not reuse passwords. Future versions may hash the value.

References:
aushack.com advisory
http://www.aushack.com/advisories/200606-contentkeeper.txt

Credit:
Patrick Webster (patrick@aushack.com)

Disclosure timeline:
15-Mar-2006 - Discovered during quick audit - common design flaw.
08-Jun-2006 - Sent to ContentKeeper support.
12-Jun-2006 - Vendor response, update expected July 2006.
22-Sep-2006 - Public disclosure.

EOF

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close