BugTraq
SEC-Consult SA 20051025-0 :: Snoopy Remote Code Execution Vulnerability Oct 25 2005 08:24PM
Bernhard Mueller (research sec-consult com) (1 replies)
Re: [Full-disclosure] SEC-Consult SA 20051025-0 :: Snoopy Remote Code Execution Vulnerability Oct 27 2005 08:12AM
Florian Weimer (fw deneb enyo de) (1 replies)
* Bernhard Mueller:

> While the vulnerability can not be exploited using the Snoopy class
> file itself, there may exist implementations which hand unchecked
> URLs from users to snoopy.

Thanks for the notice.

Have you considered in your analysis that malicious servers might
return HTTP redirects which contain suitable URLs? This requires that
the offsiteok member is set to true, though, because in the version I
looked at, only http:// URLs are considered site-local.

(Note: I haven't tried to exploit this, I just browsed the code.)

[ reply ]
Re: [Full-disclosure] SEC-Consult SA 20051025-0 :: Snoopy Remote Code Execution Vulnerability Oct 27 2005 02:14PM
SEC Consult Research (research sec-consult com)


 

Privacy Statement
Copyright 2010, SecurityFocus