Brute Force Vulnerability in Aprelium's Abyss Web Server
A vulnerability in Aprelium's Abyss Web Server 1.1.2 and earlier can permit an attacker to gain administrative access to the Web server.
February 12, 2003
Reported February 12, 2003, byThomas Adams.
VERSIONS AFFECTED
Abyss Web Server 1.1.2 and earlier
DESCRIPTION
Avulnerability in Aprelium's Abyss Web Server 1.1.2 and earlier can permit anattacker to gain administrative access to the Web server. By connecting to theremote Web management interface at http://abyss_server:9999, the attacker canuse a brute-force method to access the server. The attacker can use anindefinite number of attempts to enter a valid username and password, and thesoftware uses no delay to penalize wrong attempts. Abyss has no logging for port9999 (unlike the access.log file for port 80).
VENDOR RESPONSE
Apreliumhas been notifed and will release a patch or new version that isn't vulnerableto these conditions.
CREDIT
Discoveredby Thomas Adams.
About the Author
You May Also Like