[BMSA-2009-07] Backdoor in PyForum
--Signature=_Mon__30_Nov_2009_21_06_44_+0700_tBzvww./K9QkhlBN
Content-Type: text/plain; charset=US-ASCII
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
BLUE MOON SECURITY ADVISORY 2009-07
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
:Title: Backdoor in PyForum
:Severity: Critical
:Reporter: Blue Moon Consulting
:Products: PyForum v1.0.3
:Fixed in: --
Description
-----------
pyForum is a 100% python-based message board system based in the excellent =
web2py framework.
We have discovered a backdoor in PyForum. Anyone could force a password res=
et on behalf of other users whose emails are known. More importantly, the s=
oftware author, specifically, can obtain the new Administrator's password r=
emotely.
The problem is in module ``forumhelper.py``. A new password is generated an=
d saved in the database. Then a notification email which contains this new =
password in plaintext is sent to the user. There is no password reset confi=
rmation code or similar verification action required. This causes a mild an=
noyance, or at most an account lockout.
When it comes to Administrator account, however, the problem is more severe=
.. This default account's email is set to ``administrator@pyforum.org`` and =
can only be changed directly in the database. Therefore, new password is se=
nt to the software author by default. And since this email address is known=
, everyone can request a password reset easily.
This bug may exist in older versions and in zForum, from which pyForum deri=
ves, too.
Workaround
----------
Change Administrator's email address immediately and do not publish it anyw=
here.
Fix
---
There is no fix at the moment.
Disclosure
----------
Blue Moon Consulting adapts `RFPolicy v2.0 <http://www.wiretrip.net/rfp/pol=
icy.html>`_ in notifying vendors.
Considered this *an intentional backdoor*, we decided to alert the public i=
mmediately.
:Initial vendor contact:
--
:Vendor response:
--
:Further communication:
--
:Public disclosure: November 30, 2009
:Exploit code:
No exploit code required.
Disclaimer
----------
The information provided in this advisory is provided "as is" without warra=
nty of any kind. Blue Moon Consulting Co., Ltd disclaims all warranties, ei=
ther express or implied, including the warranties of merchantability and fi=
tness for a particular purpose. Your use of the information on the advisory=
or materials linked from the advisory is at your own risk. Blue Moon Consu=
lting Co., Ltd reserves the right to change or update this notice at any ti=
me.
--Signature=_Mon__30_Nov_2009_21_06_44_+0700_tBzvww./K9QkhlBN
Content-Type: application/pgp-signature
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (MingW32)
iEYEARECAAYFAksT0XQACgkQbKzcTD214ZcLCACdGFjem0N2zfUfzrOXOuqaIB10
cNoAnjjCiCR9tgbpnq+FvTA9cxxnXbvG
=cNII
-----END PGP SIGNATURE-----
--Signature=_Mon__30_Nov_2009_21_06_44_+0700_tBzvww./K9QkhlBN--