exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

alibaba.txt

alibaba.txt
Posted Jul 18, 2000
Authored by Prizm

Alibaba is a http server for Windows 95/98/NT which contains buffer overflows and allow remote users to execute commands remotely.

tags | exploit, remote, web, overflow
systems | windows
SHA-256 | b99bb1a99ff7c7b7a142a18a90997c406e9cfb78dc1e3847ae576d5ecfc3d442

alibaba.txt

Change Mirror Download
Application: Alibaba 2.0
Problem Type: Multiple Problems(3)
Author: Prizm<Prizm@RESENTMENT.org>
Platform(s): Windows 95/98/NT
Vendor Status: Not Informed
Vendor Website: https://csm.alcyonis.fr

Product Description
-------------------

Alibaba is a fully functional http server for windows 95/98/NT. It supports cgi among many other
things. It is easily configurable and is quite easy to use.

Bug #1: Long GET request causes alibaba server to crash
-------------------------------------------------------

The problem, as usual, is with bounds checking.

By doing:

https://www.vulnerable.host.com/[8173 bytes]

The alibaba server will shut down.

Bug #2: Problem in multiple scripts(overwrite and byte injection)
-----------------------------------------------------------------

This was found after reading a previous report on alibaba reguarding several cgi's, get32.exe
included. get16.exe, post16.exe and post32.exe all seem to include the same vulnerability as the
one in get32.exe. Bugs in get32.exe, alibaba.pl and tst.bat were found by Kerb(kerb@fnusa.com).

www.vulnerable.host.com/cgi-bin/post32.exe|echo%20>c:\text.txt
www.vulnerable.host.com/cgi-bin/post16.exe|echo%20>c:\text.txt
www.vulnerable.host.com/cgi-bin/get16.exe|echo%20>c:\text.txt

These will overwrite file.txt, or any file you specify. The get16.exe, post16.exe and post32.exe
programs will also allow the injection of code bytes into any executable file.

Bug #3: All cgi-bin scripts allow listing of alibaba directory
--------------------------------------------------------------

Simply requesting |dir%20c:\[dir] after every cgi script, you can see the contents of the
directory you specified after |dir%20 .

CGI Scripts that seem to be able to do this are: get16.exe, get32.exe, post16.exe, get32.exe,
tst.bat, tst2.bat, lsin.exe, lsindex2.bat, imapcern.exe, imapncsa.exe and aliredir.exe

Vendor Status
-------------

I didn't bother to inform the vendor because the latest version was released in 1996, so i
logically figured they had forgotten about it.


Greetings
---------

Lamagra, Scrippie, eth0, narr0w and many others...


Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    69 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close