what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

mobileTraverse.txt

mobileTraverse.txt
Posted Jul 21, 2005
Authored by Petko Petkov

Misuse of services like Google's WMLProxy and IYHY allow for proxied/anonymous attacks against web sites.

tags | advisory, web
SHA-256 | c520e4f371db2afdd4444776ffdf953c2721adc1507e695f201b5cb6b86b2db6

mobileTraverse.txt

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Security Notice: Anonymous Web Attacks via Dedicated Mobile Services
Security Risk: UNKNOWN
Publish Data: 2005 July 16

Security Researcher: Petko Petkov
Contact Information: ppetkov@gnucitizen.org
PGP Key: https://pdp.gnucitizen.org/ppetkov.asc

Synopsis
- ---------

Various Mobile Services provide malicious users with an intermediate
point to anonymously browse Web Resources and execute attacks against
them.

Affected Applications
- ----------------------

* Google's WMLProxy
* IYHY

Background
- ------------

WAP stands for Wireless Application Protocol, a communication standard
primarily designed for Information Exchange on various Wireless
Terminals such as mobile telephones. WAP devices work with WML
(Wireless Markup Language), a markup language similar to HTML but more
strict because of its XML nature. WML and HTML are totally different
in semantics. As such, there are applications located on The Internet
that are able to transcode from HTML/XHTML to WML.

Description
- ------------

An attacker can take advantage of the Google's WMLProxy Service by
sending a HTTP GET request with carefully modified URL of a malicious
nature. Such request hides the attacker's IP address and may slow down
future investigations on a successful breakin since Google's Services
are often over-trusted.

The following URL should reveal the current IP address:
https://ipchicken.com

However, a similar request proxied through WMLProxy:
https://wmlproxy.google.com/wmltrans/u=ipchicken.com
results to:
64.233.166.136 which belongs to Google Inc.

Like Google's WMLProxy, IYHY.com is HTML/XHTML transcoder, although it
is primarily designed for PDAs and Smart Phones. Still, IYHY can be
used as an intermediate point for launching anonymous attacks. For
example the following URL reveals IYHY IP address:
https://www.iyhy.com/?a=http%3A%2F%2Fipchicken.com

Attackers are able to chain Google's WMLProxy and IYHY in order to
obscure their IP address further. For example, the following URL goes
through WMLProxy and IYHY before getting to https://ipchiken.com:
https://wmlproxy.google.com/wmltrans/u=tinyurl.com@2f9g65o

Impact
- -------

Misuse of Services like Google's WMLProxy and IYHY must be considered
as a hight risk in situations where they are over-trusted. Google's
entries are often filtered out from the logs making all possible
attacks undetectable. Moreover, attackers can make use of mobile
devices to request dangerous URLs in order to compromise vulnerable
Web Applications. If such requests are not monitored by the particular
mobile network, there is no way to detect where the attack is launched
from.

Workaround
- -------------

Mobile Services can offer cleaver parameter filtering features to
prevent the execution of dangerous requests. However, it is important
to understand that simple input validation technique can be easily
circumvented. The tinyurl service can be used to obscure the dangerous
URLs, bypassing the input validation checks that an application may have.
It is also worth to mention that modifying the requests, in order to
stop certain XSS and SQL Injection attacks, may completely brake the
logic of the proxided Web Site leaving the users with unsatisfactory
results.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (MingW32)

iD8DBQFC3heXFf/6vxAyUpgRAj7FAKCHCZZPFdd/UdL018MOwPRC5ShROACcDuSR
/1zd7B7ax6+Zf5hVjSwR0Pk=
=TeEv
-----END PGP SIGNATURE-----

Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    38 Files
  • 11
    Sep 11th
    21 Files
  • 12
    Sep 12th
    40 Files
  • 13
    Sep 13th
    18 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    21 Files
  • 17
    Sep 17th
    51 Files
  • 18
    Sep 18th
    23 Files
  • 19
    Sep 19th
    48 Files
  • 20
    Sep 20th
    36 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close