|
|
|
![]() |
Vulnerability Note VU#476267Standard HTML form implementation allows access to IMAP, SMTP, NNTP, POP3, and other services via crafted HTML pageOverviewAn intruder can send certain kinds of data to services that he is not ordinarily able to reach. By crafting the data such that it is redirected through any program the victim uses to render the malicious HTML, the intruder is able send that data to any services that the victim can send data to. The malicious HTML can be embedded in documents such as an email message, web page, rich-text log or newsgroup posting.I. DescriptionAn intruder can send certain kinds of data to services that he is not ordinarily able to reach. By crafting the data such that it is redirected through any program the victim uses to render the malicious HTML, the intruder is able send that data to any services that the victim can send data to. If the victim is either tricked into clicking on a form submission button or a JavaScript program submits the form on behalf of the victim, the intruder's data may be sent to the service specified. Since the connection originates from the victim, any access control lists or restrictions designed to protect the server (such as a firewall) may not be effective. The data that the intruder is able to send is usually encoded as "multipart/form-data" by the browser, which necessarily inserts some header and encoding metadata, and is subject to any limitations of the protocol it attempts to attack.This vulnerability has been called "cross-protocol scripting."
References
The CERT/CC thanks Jochen Topf <jochen@remote.org> for reporting this vulnerability. We would also like to thank Wietse Venema and Steve Bellovin for their assistance in understanding this vulnerability. Additionally Wietse Venema coined the name "cross-protocol scripting." This document was written by Ian A. Finlay and Shawn V. Hernan.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||