Authentication Circumvention Vulnerability in BlueFace Falcon Web Server

An authentication circumvention vulnerability exists in BlueFace’s Falcon Web Server for Windows.

Ken Pfeil

February 18, 2002

1 Min Read
ITPro Today logo

Reported February 13, 2002, bySNS Research.

VERSION AFFECTED

  • Falcon Web Server for Windows

 

DESCRIPTION

An authentication circumvention vulnerability exists inBlueFace’s Falcon Web Server for Windows. A problem in the parsing of requestsmade to protected directories can let an attacker circumvent the Web server’sauthentication scheme and access any file in a protected directory withoutsupplying proper credentials. By supplying an additional backslash at thebeginning of the virtual path, an intruder can bypass authentication. Forexample, an attacker can bypass authentication of the "http://localhost/test"protected directory by accessing “http://localhost//test.”

 

VENDOR RESPONSE

 

Thevendor, BlueFace, has been notified andwill release build 2.0.0.1021 to correct this problem.

 

CREDIT
Discovered by SNSResearch.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like