Re: [SAFER 000317.EXP.1.5] Netscape Enterprise Server and '?wp' tags
From: reb () TACO COM (Phydeaux)
Date: Wed, 22 Mar 2000 20:21:09 -0500

At 08:44 PM 3/22/2000 +0000, you wrote:
This has nothing to do with the web publishing feature in
NES but rather the "Directory Indexing" function.

It seems SAFER found options a client can pass to the server
in order to use this feature. Because many people were
unaware of this function, it seems like a vulnerability.

Yes -- but this "feature" lists the content of directories even when there
is a valid index file in that directory. In such a case the server is
supposed to display the index file, not a directory listing. Clearly, the
observed behaviour is not what most system administrators would expect.

reb () taco,com

To turn it off via the Admin Interface:
Select your seb site. Then select Content
Management->Document Preferences. Under the item titled
"Directory Indexing" select none.

To turn it off in the config:
Look for this option in obj.conf:
Service method="(GET|HEAD)" type="magnus-internal/directory"

Set fn equal to: fn="send-error"



Hello all,

Netscape ENT 3.6 SP3 -or maybe it's SP2- on NT4.0 SP4,
vulnerable, even though
WebPublishing has never (not even just to try it out) been
enabled.  All
commands (plus more that don't work) listed in bulletin are
contained in the


S.A.F.E.R. Security Bulletin
TITLE    : Netscape Enterprise Server and '?wp' tags
and '?wp' tags
DATE     : March 17, 2000
NATURE   : Remote user can obtain list of directories on Netscape
list of directories on Netscape
Enterprise Server
AFFECTED : Netscape Enterprise Server
Problem exists in Netscape Enterprise Server that can allow remote user
Server that can allow remote user
to obtain list of directories and subdirectories on the server.
subdirectories on the server.
Netscape Enterprise Server with 'Web Publishing' enabled can be tricked
Publishing' enabled can be tricked
into displaying the list of directories and subdirectories, if user
directories and subdirectories, if user
supplies certain 'tags'. For example:
http://www.example.com/?wp-cs-dump
will reveal the contents of the root directory on that web server.
directory on that web server.
Contents of subdirectories can be obtained as well. Other tags that can
obtained as well. Other tags that can
be used are:
?wp-ver-info
?wp-html-rend
?wp-usr-prop
?wp-ver-diff
?wp-verify-link
?wp-start-ver
?wp-stop-ver
?wp-uncheckout
FIXES:
Disable 'Web Publishing'. It is safe to assume that 'Web Publishing' is
to assume that 'Web Publishing' is
not the only feature that will 'activate' this problem. We have found
'activate' this problem. We have found
few servers running Netscape Enterprise Server that did not have 'Web
Enterprise Server that did not have 'Web
Publishing' enabled, but were still vulnerable to this problem. Until
vulnerable to this problem. Until
Netscape makes an official response and clarify what is the cause of
and clarify what is the cause of
this problem, it is advised that you test your server against this
test your server against this
vulnerability, and if you are vulnerable, try to disable certain
vulnerable, try to disable certain
features and services.
Netscape has been contacted on many occasions, but has failed to
occasions, but has failed to
respond.
S.A.F.E.R. - Security Alert For Entreprise Resources
Entreprise Resources
Copyright (c) 2000 The Relay Group
Relay Group
http://safer.siamrelay.com
http://safer.siamrelay.com
---
security () relaygroup com
