################################################
OneWorldStore Critical Failure
vendor url:http://oneworldstore.com/
advisory:http://lostmon.blogspot.com/2005/04/
oneworldstore-critical-failure.html
vendor confirmed:yes exploit available: yes
OSVDB ID:15724
Secunia: SA15057
BID:13322
Securitytracker: 1013782
################################################
OneWorldStore contains a flaw that may allow a malicious user to
crash the application. The issue is triggered when a remote user
call directly '/owConnections/chksettings.asp' script occurs. It is
possible that the flaw may allow resulting in a loss of availability.
########
versions
#######
OneWorldStore basic
OneWorldStore free
OneWorldStore enterprise
########
solution:
########
OneWorldStore has release a wrokaround
http://www.oneworldstore.com/support_security_issue_updates.asp
#April_20_2005_Lostmon
workaround:
--delete (or rename) the /owConnections/chksettings.asp file.
timeline
discovered 19 april 2005
vendor notify 19 april 2005
vendor response:20 april 2005
vendor solution: 20 april 2005
proof of concept:
Failure method:
Run this file in a browser:
http://[domain name]/owConnections/chksettings.asp
Upon execution the site will shut down until a fix is applied. Each
site's fix is different. However, no data will be lost or exposed.
RESOULTION:
Delete the /owConnections/chksettings.asp prior to being hacked.
OneWorldStore Editions no longer use the /owConnections/chksettings.asp file.
this crashes the application, and a user can re-start only to step 2
without the fix..they need the fix to prevent it from happening
again
We would like to thank Lostmon for notifying us of these issues. Our
turnaround time for applying the fixes and releasing the patches was
approximately 5 hours. We have also asked him to post his advisory,
with our fix, on his website to help get the word out about the patch.
########### END ##############
thnx to estrella to be my ligth
thnx to all http://www.osvdb.org Team
thnx to all who day after day support me !!!
thnx to vendor very fast respose and very fast release a fix good work !!
thnx to icaro he is investigate with me :D
--
atentamente:
Lostmon (lostmon@gmail.com)
Web-Blog: http://lostmon.blogspot.com/
Data Mangle of: http://www.osvdb.org
--
La curiosidad es lo que hace mover la mente...