Full Disclosure mailing list archives

BF, CSRF, and IAA vulnerabilities in websecurity.com.ua


From: Julius Kivimäki <julius.kivimaki () gmail com>
Date: Mon, 31 Dec 2012 15:55:46 +0200

Hello list!

I want to warn you about multiple extremely severe vulnerabilities in
websecurity.com.ua.

These are Brute Force and Insufficient Anti-automation vulnerabilities in
websecurity.com.ua. These vulnerability is very serious and could affect
million of people.

-------------------------
Affected products:
-------------------------

Vulnerable are all versions of websecurity.com.ua.

----------
Details:
----------

Brute Force (WASC-11):

In ftp server (websecurity.com.ua:21) there is no protection from Brute
Force
attacks.

Cross-Site Request Forgery (WASC-09):

Lack of captcha in login form (http://websecurity.com.ua:21/) can be used
for
different attacks - for CSRF-attack to login into account (remote login - to
conduct attacks on vulnerabilities inside of account), for automated
entering into account, for phishing and other automated attacks. Which you
can read about in the article "Attacks on unprotected login forms"
(
http://lists.webappsec.org/pipermail/websecurity_lists.webappsec.org/2011-April/007773.html
).

Insufficient Anti-automation (WASC-21):

In login form there is no protection against automated request, which allow
to picking up logins in automated way by attacking on login function.
------------
Timeline:
------------

2012.06.28 - announced at my site about websecurity.com.ua.
2012.06.28 - informed developers about the first part of vulnerabilities in
websecurity.com.ua.
2012.06.30 - informed developers about the second part of vulnerabilities in
websecurity.com.ua.
2012.07.26 - announced at my site about websecurity.com.ua.
2012.07.28 - informed developers about vulnerabilities in websecurity.com.ua
and reminded about previous two letters I had sent to them with carrier
pigeons.
2012.07.28-2012.10.31 - multiple attempts to contact the owners of
websecurity.com.ua
were ignored by the owners.
2012.11.02 - developers responded "fuck off and kill urself irl!".
2012.12.31 - disclosed on the list

Best wishes & regards,
MustLive
Security master extraordinaire, master sysadmin
http://websecurity.com.ua
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Current thread: