Home page logo

bugtraq logo Bugtraq mailing list archives

Re: Sambar Server Beta BUG..
From: posicks () ESPN COM (Posick, Steve)
Date: Wed, 10 Jun 1998 15:15:34 -0400

There is also a buffer overrun in the logging code and a MAJOR hole in
the mailit script that allow for remote execution
of system commands.

In both cases I have notified Tod Sambar and they are hopefully

-----Original Message-----
From:   Michiel de Weerd [SMTP:webmaster () FOCUS DEMON NL]
Sent:   Wednesday, June 10, 1998 12:13 PM
Subject:        Sambar Server Beta BUG..

Sambar Server Beta's have a serious bug! it is possible to view the
victim's HDD.

This is how it's done:

Asume you find a computer running Sambar Server by searching the
Internet with these key-words: +sambar +server +v4.1

If you find a site like: http://www.site.net/

then do a test, run a little perl script...


Now you see the complete environment of the victims computer,
his path. Now you can try to login as the administrator by adding
to the url: /session/adminlogin?RCpage=/sysadmin/index.stm

so: http://www.site.net/session/adminlogin?RCpage=/sysadmin/index.stm

The default login is: admin and the default password is blank.

If the victim hasn't changed his settings, you now can control his

Another feature is to view the victims HDD. If you were able to run
perl script you should also be able (in most cases) to view
from his path. Most people have c:/program files and c:/windows in
path line, so what you can do is:

http://www.site.net/c:/program files/sambar41


1) Upgrade to a non-beta version of Sambar Server.
2) Don't alow directory browsing if index.html or default.html isn't
3) Change the admin username and password before someone else changes
for you.

CC to Tod Sambar - http://www.sambar.com

  By Date           By Thread  

Current thread:
  • Sambar Server Beta BUG.. Michiel de Weerd (Jun 10)
    • <Possible follow-ups>
    • Re: Sambar Server Beta BUG.. Posick, Steve (Jun 10)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]