Wednesday, May 16, 2012

Our CTO, Gordon MacKay Speaks @ Alamo ISSA Quarterly Chapter Meeting

Our thanks to the Alamo ISSA Chapter for hosting our CTO, Gordon MacKay yesterday as a speaker along with Ira Winkler and Dan Teal from CoreTrace.  Great venue and attendance!

Transparency Statement:  DDI is a Gold Sponsor for the Alamo ISSA Chapter.

Epicor Returns Management SOAP-Based Blind SQL Injection

DDIVRT-2012-44 Epicor Returns Management SOAP-Based Blind SQL Injection

Follow Us on Twitter!

Severity: High

Date Discovered: April 12, 2012

Discovered By: Chris Graham
Additional Discovered By: r@b13$

Vulnerability Description:

Digital Defense, Inc. (DDI) has discovered a blind SQL injection vulnerability in the Epicor Returns Management software SOAP interface.  Left unremediated, this vulnerability could be leveraged by an attacker to execute arbitrary SQL commands and extract information from the backend database using standard SQL exploitation techniques. Additionally, an attacker may be able to leverage this flaw to compromise the database server host operating system.

Solution Description:

Epicor Software Corporation has now confirmed they have now contacted the customers affected, and have made an update available to address this vulnerability. As such, DDI recommends restricting access to the affected port/interface until installing the Epicor update or implementing another workaround to address the issue.

It should be noted that Epicor has advised DDI that the codebase for Returns Management software may differ significantly from customer to customer. Epicor has suggested that some customer installs may not contain this specific vulnerability as a result of this codebase variability.

DDI recommends that any customer currently utilizing Epicor Returns Management software within their enterprise install the update Epicor has made available and, if concerned about the applicability of the update, log a support call with Epicor directly to determine if their codebase contains this vulnerability.

Tested Systems / Software:

Epicor Returns Management
Windows Server 2003
Microsoft SQL Server 2000
Platform: Apache Tomcat/4.1.31

Vendor Name: Epicor Software Corporation
Vendor Website: www.epicor.com

Monday, April 30, 2012

ACTi Web Configurator cgi-bin Directory Traversal

DDIVRT-2012-41 ACTi Web Configurator cgi-bin Directory Traversal


Follow Us on Twitter!

Severity: High

Date Discovered: March 8, 2012

Credit: shmoov and r@b13$

Vulnerability Description
The ACTi Web Configurator 3.0 for ACTi IP Surveillance Cameras contains a directory traversal vulnerability within the cgi-bin directory. An unauthenticated remote attacker can use this vulnerability to retrieve arbitrary files that are located outside the root of the web server.

Solution Description
The production of the cameras employing this version of the ACTi Web Configurator have been discontinued. However, a firmware upgrade which addresses the issue is available for download from the ACTi support team. Please contact the ACTi support team to retrieve the firmware upgrade and instructions on how to apply the changes.

Tested Systems / Software
ACTi Web Configurator 3.0 - camera version unknown

Vendor Contact
Vendor Name: ACTi Corporation

PacketVideo TwonkyServer and TwonkyMedia Directory Traversal

DDIVRT-2012-40 PacketVideo TwonkyServer and TwonkyMedia Directory Traversal

Follow Us on Twitter!

Severity
--------
High

Date Discovered
---------------
March 12, 2012

Discovered By
-------------
Credit: r@b13$

Vulnerability Description
-------------------------
Multiple PacketVideo products contain a directory traversal vulnerability within the web server that is running on port 9000. These products are vulnerable to the attack regardless of having configured the “Secured Server Settings” which are available on the Advanced configuration page. Susceptible products include the Twonky 7.0 Special and the TwonkyManager 3.0.

An unauthenticated remote attacker can use this vulnerability to retrieve arbitrary files that are located outside the root of the web server.

Solution Description
--------------------
PacketVideo has not provided a patch for this vulnerability. Until a patch is released by the vendor, it is recommended that access to the web server be restricted to authorized hosts only.

Tested Systems / Software
-------------------------
Twonky 7.0 Special on Windows Vista
TwonkyManager 3.0 on Windows Vista

Vendor Contact
--------------
Vendor Name: PacketVideo Corporation 



Monday, March 12, 2012

Disclosures in the Works!

We've got two new disclosures in the works....stay tuned!

Monday, February 13, 2012

SolarWinds Storage Manager Server SQL Injection Authentication Bypass - Update!

SolarWinds has addressed the issue with a hot-fix for version 5.1.2 of Storage Manager, Storage Profiler, and Backup Profiler. Current SolarWinds customers can download the hot-fix from the SolarWinds Customer Portal.

SolarWinds customers running versions of the affected software that are prior to version 5.1.2 must upgrade to version 5.1.2 before applying the patch. Customers can obtain the latest version of the software from the Customer Portal.

[1] - http://www.solarwinds.com/support/

[2] - http://thwack.solarwinds.com/forums/63/storage-management/286/general-discussion/36983/hotfix-for-storage-manager-sql/

[3] - http://www.solarwinds.com/documentation/storage/storagemanager/docs/ReleaseNotes/vulnerability.htm

Thursday, February 2, 2012