|
Digital Security Research Group [DSecRG] Advisory
http://dsecrg.com/pages/vul/show.php?id=161
Various XSS and XSRF vulnerabilities were identified in the Alteon OS Browser-Based
Interface (BBI).
Application: Alteon OS BBI
Versions Affected: <= 21.0.8.3 and may be higher ( <=25.1.0.0 )
Vendor URL: http://www.nortelnetworks.com; http://radware.com
Bug: XSS ans XSRF Vulnerabilities
Exploits: YES
Reported: 11.08.2009
Secondly Reported: 07.09.2009
Final Reported: 28.10.2009
Date of Public Advisory: 16.11.2009
Solution: YES (Non official)
Author: Sintsov Alexey from Digital Security Research Group [DSecRG]
Description
***********
Browser-Based Interface (BBI) software is included in the Nortel Networks(vesrions < 25.0.0.0) and Radware
family of switches. The BBI software lets you use your Web browser to access switch
information and statistics, to perform switch configuration via the Internet. This
vulnerabilities allow remote attackers to change the switch configuration.
Details:
*******
1) XSRF
An attacker may exploit this issue to perform certain administrative actions,
e.g. change using predictable URL requests once the user has authenticated and
obtained a valid session with the switch.
Example
*******
PoC (Change banner and apply):
Solution:
*********
We have no answer from Radware about two month. So we don't know about
this vuln. in versions 25.0.1.0 - 25.1.0.0.
Here are our recommendations:
a) Turn off BBI.
b) Change default SSHd port.
/c/sys/access/https/https d
/c/sys/access/http d
/c/sys/access/sshd/sshport 42
c) Allow access to SSH and BBI only for trusted machines and networks;
References
**********
http://dsecrg.com/pages/vul/show.php?id=161
About
*****
Digital Security is leading IT security company in Russia, providing information security consulting, audit and penetration testing services, risk analysis and ISMS-related services and certification for ISO/IEC 27001:2005 and PCI DSS standards. Digital Security Research Group focuses on web application and database security problems with vulnerability reports, advisories and whitepapers posted regularly on our website.
Contact: research [at] dsecrg [dot] com
http://www.dsecrg.com