Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting
Rule:  
alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS $HTTP_PORTS (msg:"WEB-CGI count.cgi access"; flow:to_server,established; uricontent:"/c
ount.cgi"; nocase; reference:bugtraq,128; reference:cve,CVE-1999-0021; reference:nessus,10049; classtype:web-application-activity; s
id:1149; rev:9;)
--
Sid:
1149

--
Summary:
Wwwcount (count.cgi) is a very popular CGI program used to track website usage.

--
Impact:
Will allow access as whatever this process is running as.

--
Detailed Information:
In particular, it enumerates the number of hits on given webpages and increments them on a 'counter'. In October of 1997 two remotel
y exploitable problems were discovered with this program. The first problem was somewhat innocuous in that it only allowed remote us
ers to view .GIF files they were not supposed to have access to. This may be dangerous if the site contains sensitive data in .GIF f
iles such as demographic/financial data in charts etc.

The second and most serious problem is a buffer overflow in QUERY_STRING enviroment variable handled by the program. In essence a re
mote user can send an overloy long query to the program and overflow a buffer in order to execute their own commands as whatever pri
velage level the program is running as.

--
Attack Scenarios:

--
Ease of Attack:
Exploit code available
--
False Positives:
A none vulnerable version of the app will trigger alarm as only looks for count.cgi during a established connection.
--
False Negatives:

--
Corrective Action:
If you are running version 2.3 of Wwwcount it is suggested you upgrade immediately. In the meantime you may wish to consider removin
g the execution bit on this program. Versions 2.4 and above of this software are available at: 
http://www.fccc.edu/users/muquit/Count.html 
Do you need help?X
-- Contributors: -- Additional References: http://securityfocus.com/bid/128/info/ http://icat.nist.gov/icat.cfm?cvename=CVE-1999-0021

Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library