« VOIPPACK 1.4 with added support for Cisco and Trixbox | Main | VOIPPACK update for February 2010 brings faster VoIP cracking and destruction »
Tuesday
Jun012010

Using XSS to switch off dotDefender 4.0

AppliCure's dotDefender version 4.0 had a security flaw in the log viewing feature of the administrative interface. We just published an advisory for this vulnerability. Here's the interesting part:

"The log viewer facility in dotDefender does not properly htmlencode user supplied input. This leads to a cross site scripting vulnerability when the log viewer displays HTTP headers."


The following video shows how an attacker can make use of cross site scripting to get the system administrator to automatically switch off dotDefender. This effectively disables the WAF, leaving the web application exposed to any attacks that said WAF was supposed to protect against.

Advisory: ES-20100601

Video demo: http://vimeo.com/12132622



FAQ

But doesn't the attacker need to reach the administrator interface?

Nope - its the administrator's authenticated web browser that disables the WAF due to the injected javascript. Therefore the attacker just needs to reach the website protected by the WAF.

References (3)

References allow you to track sources for this article, as well as articles that were written in response to this article.

Reader Comments (1)

[...] in the log viewer facility of the dotDefender admin interface.  Watch the video below for a more in depth explanation of the attack.  From the below video one can also learn and understand the importance of having secure web [...]

PostPost a New Comment

Enter your information below to add a new comment.

My response is on my own website »
Author Email (optional):
Author URL (optional):
Post:
 
Some HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong>