Results 1 to 4 of 4

Thread: BSCV Insecure Default Installation Vulnerability

  1. #1

    BSCV Insecure Default Installation Vulnerability

    BSCW (Basic Support for Cooperative Work) is a web-based groupware application, allowing users to share a workspace via a web interface. It runs on Microsoft Windows NT/2000 systems, as well as a number of Unix variants.
    The default installation allows users to self-register, potentially allowing untrusted users to access the service.

    This may provide a window of opportunity for an untrusted, malicious user to access the service to exploit known issues. One example of an existing issue that may be exploited as a result of untrusted users being able to self-register is BugTraq ID 3776 "BSCW Remote Command Execution Vulnerability".

    EXPLOIT

    The self-registration interface can be accessed with the following example:

    http://your.bscwserver.url/pub/english.cgi?op=rmail

    Read www.xatrix.org if you want to be inform!

  2. #2
    Senior Member
    Join Date
    Nov 2001
    Posts
    114

    Thumbs up

    thanks for the xatrix.org link. I'm always looking for current computer related news.

    i keep getting a DNS error with your other link though...

    thanks again

  3. #3

    Smile

    We are here for You, and if you have any suggestion, just reply at our forum...
    Thanks again !!!

  4. #4
    Senior Member
    Join Date
    Dec 2001
    Posts
    291
    definately a righteously tasty link there KOB...

    thx!

    ~THEJRC~
    ~THEJRC~
    I\'ll preach my pessimism right out loud to anyone that listens!
    I\'m not afraid to be alive.... I\'m afraid to be alone.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •