[BMSA-2009-07] Backdoor in PyForum

看板Bugtraq作者時間16年前 (2009/12/01 06:01), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/1
--Signature=_Mon__30_Nov_2009_21_06_44_+0700_tBzvww./K9QkhlBN Content-Type: text/plain; charset=US-ASCII Content-Disposition: inline Content-Transfer-Encoding: quoted-printable BLUE MOON SECURITY ADVISORY 2009-07 =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D :Title: Backdoor in PyForum :Severity: Critical :Reporter: Blue Moon Consulting :Products: PyForum v1.0.3 :Fixed in: -- Description ----------- pyForum is a 100% python-based message board system based in the excellent = web2py framework. We have discovered a backdoor in PyForum. Anyone could force a password res= et on behalf of other users whose emails are known. More importantly, the s= oftware author, specifically, can obtain the new Administrator's password r= emotely. The problem is in module ``forumhelper.py``. A new password is generated an= d saved in the database. Then a notification email which contains this new = password in plaintext is sent to the user. There is no password reset confi= rmation code or similar verification action required. This causes a mild an= noyance, or at most an account lockout. When it comes to Administrator account, however, the problem is more severe= .. This default account's email is set to ``administrator@pyforum.org`` and = can only be changed directly in the database. Therefore, new password is se= nt to the software author by default. And since this email address is known= , everyone can request a password reset easily. This bug may exist in older versions and in zForum, from which pyForum deri= ves, too. Workaround ---------- Change Administrator's email address immediately and do not publish it anyw= here. Fix --- There is no fix at the moment. Disclosure ---------- Blue Moon Consulting adapts `RFPolicy v2.0 <http://www.wiretrip.net/rfp/pol= icy.html>`_ in notifying vendors. Considered this *an intentional backdoor*, we decided to alert the public i= mmediately. :Initial vendor contact: -- :Vendor response: -- :Further communication: -- :Public disclosure: November 30, 2009 :Exploit code: No exploit code required. Disclaimer ---------- The information provided in this advisory is provided "as is" without warra= nty of any kind. Blue Moon Consulting Co., Ltd disclaims all warranties, ei= ther express or implied, including the warranties of merchantability and fi= tness for a particular purpose. Your use of the information on the advisory= or materials linked from the advisory is at your own risk. Blue Moon Consu= lting Co., Ltd reserves the right to change or update this notice at any ti= me. --Signature=_Mon__30_Nov_2009_21_06_44_+0700_tBzvww./K9QkhlBN Content-Type: application/pgp-signature -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (MingW32) iEYEARECAAYFAksT0XQACgkQbKzcTD214ZcLCACdGFjem0N2zfUfzrOXOuqaIB10 cNoAnjjCiCR9tgbpnq+FvTA9cxxnXbvG =cNII -----END PGP SIGNATURE----- --Signature=_Mon__30_Nov_2009_21_06_44_+0700_tBzvww./K9QkhlBN--
文章代碼(AID): #1B542XQx (Bugtraq)