Brute Force Vulnerability in Aprelium's Abyss Web Server

A vulnerability in Aprelium's Abyss Web Server 1.1.2 and earlier can permit an attacker to gain administrative access to the Web server.

Ken Pfeil

February 12, 2003

1 Min Read
ITPro Today logo

Reported February 12, 2003, byThomas Adams.

 

 

VERSIONS AFFECTED

 

  • Abyss Web Server 1.1.2 and earlier

 

DESCRIPTION

 

Avulnerability in Aprelium's Abyss Web Server 1.1.2 and earlier can permit anattacker to gain administrative access to the Web server. By connecting to theremote Web management interface at http://abyss_server:9999, the attacker canuse a brute-force method to access the server. The attacker can use anindefinite number of attempts to enter a valid username and password, and thesoftware uses no delay to penalize wrong attempts. Abyss has no logging for port9999 (unlike the access.log file for port 80).

 

VENDOR RESPONSE

 

Apreliumhas been notifed and will release a patch or new version that isn't vulnerableto these conditions.

 

CREDIT          

Discoveredby Thomas Adams.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like