-
January 6th, 2002, 01:35 AM
#1
BSCV Insecure Default Installation Vulnerability
BSCW (Basic Support for Cooperative Work) is a web-based groupware application, allowing users to share a workspace via a web interface. It runs on Microsoft Windows NT/2000 systems, as well as a number of Unix variants.
The default installation allows users to self-register, potentially allowing untrusted users to access the service.
This may provide a window of opportunity for an untrusted, malicious user to access the service to exploit known issues. One example of an existing issue that may be exploited as a result of untrusted users being able to self-register is BugTraq ID 3776 "BSCW Remote Command Execution Vulnerability".
EXPLOIT
The self-registration interface can be accessed with the following example:
http://your.bscwserver.url/pub/english.cgi?op=rmail
Read www.xatrix.org if you want to be inform!
-
January 6th, 2002, 02:11 AM
#2
thanks for the xatrix.org link. I'm always looking for current computer related news.
i keep getting a DNS error with your other link though...
thanks again
-
January 6th, 2002, 11:10 PM
#3
We are here for You, and if you have any suggestion, just reply at our forum...
Thanks again !!!
-
January 6th, 2002, 11:36 PM
#4
definately a righteously tasty link there KOB...
thx!
~THEJRC~
~THEJRC~
I\'ll preach my pessimism right out loud to anyone that listens!
I\'m not afraid to be alive.... I\'m afraid to be alone.
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|