Home page logo
/

fulldisclosure logo Full Disclosure mailing list archives

Fail2ban 0.8.9, Denial of Service (Apache rules only)
From: Krzysztof Katowicz-Kowalewski <vnd () vndh net>
Date: Tue, 11 Jun 2013 11:58:51 +0200

Version 0.8.9 (latest) of Fail2ban allows to perform remote denial of service for arbitrary chosen IP address. Address 
listed on Fail2ban's whitelist are not affected. The vulnerability exists in Apache rules and it is caused by improper 
validation of a log file by regular expression. Malicious user can easily inject his own data to analyzed logs and 
deceive monitoring engine.

Affected files:
/filter.d/apache-auth.conf
/filter.d/apache-nohome.conf
/filter.d/apache-noscript.conf
/filter.d/apache-overflows.conf

Time frames:
01.06.2013 - Cyril Jaquier (contact section) has been informed about the vulnerability (no response)
08.06.2013 - The vulnerability has been released to the public.

More information, including proof of concept and patches is available here:
https://vndh.net/note:fail2ban-089-denial-service

Attachment: signature.asc
Description: Message signed with OpenPGP using GPGMail

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

  By Date           By Thread  

Current thread:
  • Fail2ban 0.8.9, Denial of Service (Apache rules only) Krzysztof Katowicz-Kowalewski (Jun 11)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]