Authentication Circumvention Vulnerability in BlueFace Falcon Web Server
An authentication circumvention vulnerability exists in BlueFace’s Falcon Web Server for Windows.
February 18, 2002
Reported February 13, 2002, bySNS Research.
VERSION AFFECTED
Falcon Web Server for Windows
DESCRIPTION
An authentication circumvention vulnerability exists inBlueFace’s Falcon Web Server for Windows. A problem in the parsing of requestsmade to protected directories can let an attacker circumvent the Web server’sauthentication scheme and access any file in a protected directory withoutsupplying proper credentials. By supplying an additional backslash at thebeginning of the virtual path, an intruder can bypass authentication. Forexample, an attacker can bypass authentication of the "http://localhost/test"protected directory by accessing “http://localhost//test.”
VENDOR RESPONSE
Thevendor, BlueFace, has been notified andwill release build 2.0.0.1021 to correct this problem.
CREDIT
Discovered by SNSResearch.
About the Author
You May Also Like