lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <k2w875432851004242331v5f27f248wbd0cca93a882ff44@mail.gmail.com>
Date: Sun, 25 Apr 2010 14:31:48 +0800
From: YGN Ethical Hacker Group <lists@...g.net>
To: undisclosed-recipients:;
Subject: HP System Management Homepage(SMH) | URL
	Redirection Abuse

=============================================================
 HP System Management Homepage(SMH) | URL Redirection Abuse
=============================================================

by
Aung Khant
YGN Ethical Hacker Group, Myanmar
http://yehg.net/

Product:
HP System Management Homepage

Description:
Consolidated system management information helps IT Administrators predict,
diagnose, and rapidly respond to potential and actual system failures
for a single server.

Vendor: HP Inc (http://www.hp.com)

Vulnerability Affected:
URL Redirection Abuse

Versions tested:
2.x.x.x

Versions affected:
2.x.x.x
Other versions(3.x) might be affected as well.

Date published: 04-25-2010

Severity: Medium

Vulnerability Detail:
Attacker can lure victim to redirect to his choice of malicious site via the
trusted vulnerable SMH url. From there, serious attacks such as
browser exploits can be performed
to compromise victim's OS.

POC URL:
http://x.x.x.x:2301/red2301.html?RedirectUrl=evil@...acker.com

Solution:
 - Remove red3201.html under hpsmh\data\htdocs\ directory OR
 - sanitize RedirectUrl variable OR
 - Wait for Vendor's fix in next 4-6 months

X-Ref:
OWASP-TOP10-2010: A8 - Unvalidated Redirects and Forwards
WASC-38 URL Redirector Abuse
CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

Advisory URL:
http://yehg.net/lab/pr0js/advisories/hp_system_management_homepage_url_redirection_abuse

Disclosure Timeline:
03-10-2010: found vulnerability
04-12-2010: contacted vendor @
http://welcome.hp.com/country/us/en/sftware_security.html
04-12-2010: vendor responded
04-14-2010: vendor confirmed and would release fix within 4 to 6 months.
04-25-2010: disclosed

Vendor Response (HP Software Security Response Team):
>We are able to duplicate the vulnerability.
>I expect we can resolve the vulnerability in the next SMH patch.
>Because regularly scheduled patches are easier for customers to incorporate
>we prefer to resolve vulnerabilities in those patches rather than in special hotfixes.
>I don't have a patch schedule, but normally SMH is patched every four to six months.

----------------
# yehg [04-25-2010]

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ