Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: Full Disclosure: Full-Disclosure

radware AppWall Web Application Firewall: Source code disclosure on management interface

 

 

Full Disclosure full-disclosure RSS feed   Index | Next | Previous | View Threaded


sec08003 at fh-hagenberg

Jun 30, 2009, 11:13 PM

Post #1 of 3 (274 views)
Permalink
radware AppWall Web Application Firewall: Source code disclosure on management interface

Security Advisory

---------------------------------------

Vulnerable Software: radware AppWall Web Application Firewall

Vulnerable Version: Gateway Version 4.6.0.2 / AppWall Version
1.0.2.6

Homepage: http://www.radware.com/

Found by: Michael Kirchner, Wolfgang
Neudorfer, Lukas Nothdurfter (Team h4ck!nb3rg)

Impact: Source code disclosure on
management interface





Product Description

---------------------------------------

Radware's AppWall is a Web application firewall (WAF) appliance that
secures Web applications. It enables PCI compliance by mitigating Web
application security threats and vulnerabilities to prevent data theft
and manipulation of sensitive corporate and customer information.
AppWall incorporates advanced, patent-protected Web application security
filtering technologies to seamlessly detect threats, block attacks and
report events.

[Source:
http://www.radware.com/Products/ApplicationDelivery/AppWall/default.aspx
]





Vulnerability Description

---------------------------------------

The radware AppWall Web Application Firewall operates as a reverse proxy
between the clients and the web server to be protected. All HTTP
requests are checked before being forwarded to the web server. The
system can be administered via a seperate management interface which is
normally not accessible for external users. The web interface is
realised using the PHP programming language. Some of the functionality
is stored in include files and embedded when needed. The files have a
*.inc extension and are not interpreted by the web server. A
user/attacker with access to the web management interface can therefore
access parts of the product source code by requesting the included files
directly.





Proof of Conept

---------------------------------------

The following example requests reveal product source code enabling an
attacker to search for further implementation vulnerabilities:

https://appwall/Management/funcs.inc

https://appwall/Management/defines.inc

https://appwall/Management/msg.inc





Vulnerable Versions

---------------------------------------

The tested version was Gateway Version 4.6.0.2 / AppWall Version
1.0.2.6. Prior versions are also likely to be vulnerable.





Patch

---------------------------------------

Currently we are not aware of any patch or update available.





Contact Timeline

---------------------------------------

2009-06-01: Vendor informed

2009-06-15: No response yet. Vendor contacted again.

2009-06-15: Initial vendor reply (Support ticket opened)

2009-07-01: No response yet as far as the vulnerability is concerned.
Public release





Further information

---------------------------------------

Information about the web application firewall project this advisory
originates from can be found at:

http://www.h4ck1nb3rg.at/wafs/


ShakedV at Radware

Jul 2, 2009, 4:23 AM

Post #2 of 3 (236 views)
Permalink
Re: radware AppWall Web Application Firewall: Source code disclosure on management interface [In reply to]

Radware team has completed analysis of the reported issue, concluding
that no AppWall customer using the product according to Radware
deployment recommendations would be exposed to vulnerability as a result
of this issue. This is due to the facts that this issue exists only on
the management interface that is recommended to be connection to
internal LAN only, and that it does not allow performing any actions
that would influence machine functionality.
Nevertheless, in order to enforce our commitment to deliver top
security solution to our customers, Radware will supply a fix for this
issue within its upcoming AppWall release.

Shaked Vax
AppWall Product Manager
ShakedV[at]radware.com


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


3APA3A at SECURITY

Jul 3, 2009, 5:58 AM

Post #3 of 3 (226 views)
Permalink
Re: radware AppWall Web Application Firewall: Source code disclosure on management interface [In reply to]

Dear Shaked Vax,

Are you sure Radware Team have analysed reflected attack via user's
browser (AppWall administrator visits malcrafted page, page redirects
his request to AppWall) before excluding remote vector?

--Thursday, July 2, 2009, 3:23:16 PM, you wrote to full-disclosure[at]lists.grok.org.uk:

SV> Radware team has completed analysis of the reported issue, concluding
SV> that no AppWall customer using the product according to Radware
SV> deployment recommendations would be exposed to vulnerability as a result
SV> of this issue. This is due to the facts that this issue exists only on
SV> the management interface that is recommended to be connection to
SV> internal LAN only, and that it does not allow performing any actions
SV> that would influence machine functionality.
SV> Nevertheless, in order to enforce our commitment to deliver top
SV> security solution to our customers, Radware will supply a fix for this
SV> issue within its upcoming AppWall release.

SV> Shaked Vax
SV> AppWall Product Manager
SV> ShakedV[at]radware.com


SV> _______________________________________________
SV> Full-Disclosure - We believe in it.
SV> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
SV> Hosted and sponsored by Secunia - http://secunia.com/


--
Skype: Vladimir.Dubrovin
~/ZARAZA http://securityvulns.com/
Но Гарри... я безусловно отдаю предпочтение ему, за
высокую питательность и какое-то особенно нежное мясо. (Твен)

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Full Disclosure full-disclosure RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact lists@gossamer-threads.com
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.