Relative Path Vulnerability in WinWrapper Professional 2.0

A vulnerability exists in ASCII NT Products WinWrapper 2.0 Professional firewall software that lets an attacker read files on the vulnerable system under the local system security context.

Ken Pfeil

August 26, 2001

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported August 21, 2001, by AraiYu.

VERSION AFFECTED

  • ASCII NT Products WinWrapper 2.0 Professional

 

DESCRIPTION
Avulnerability exists in ASCII NT Products WinWrapper 2.0 Professional firewallsoftware that lets an attacker read files on the vulnerable system under thelocal system security context. By using the remote service port (4096) that thesystem opens for Web-based administration, an attacker can traverse the remotesystem file structure using relative paths to read arbitrary data.

 

DEMONSTRATION

Arai Yu posted the following example asproof-of-concept:

 

http://IP_Address_of_WinWrapper:4096/../../../winnt/repair/sam

 

Typing the preceding line downloads a copy of the SAMdatabase from the vulnerable system.

 

VENDOR RESPONSE

The vendor, ASCIINT Products, has released version 2.0.1that fixes this vulnerability.

 

CREDIT
Discovered by AraiYu.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like