Microsoft Windows 95/Windows for Workgroups – ‘smbclient’ Directory Traversal

Microsoft Windows 95/Windows for Workgroups – ‘smbclient’ Directory Traversal

漏洞ID 1053341 漏洞类型
发布时间 1995-10-30 更新时间 1995-10-30
图片[1]-Microsoft Windows 95/Windows for Workgroups – ‘smbclient’ Directory Traversal-安全小百科CVE编号 N/A
图片[2]-Microsoft Windows 95/Windows for Workgroups – ‘smbclient’ Directory Traversal-安全小百科CNNVD-ID N/A
漏洞平台 Windows CVSS评分 N/A
|漏洞来源
https://www.exploit-db.com/exploits/20371
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
source: http://www.securityfocus.com/bid/1884/info

Samba is a set of of programs that allow Windows® clients access to a Unix server's filespace and printers over NetBIOS. A directory traversal vulnerability exists in Microsoft's implementation of the SMB file and print sharing protocol for Windows 95 build 490.r6 and Windows for Workgroups.

smbclient normally rejects '/../' sequences in user-supplied pathnames before submitting them to the server. This prevents an attacker from traversing the server's directory tree and accessing files which would normally be inaccessible.

Because the check for '/../' is peformed by smbclient, the server assumes the client is filtering invalid input. However, a modified client can be made to accept the restricted '/../' sequences, appending these characters to filenames and submitting them as a request to the server.

Since the server leaves this input validation up to the client, once the server is provided with path information which contains '/../', it assumes it to be valid. As a result, a directory traversal becomes possible, granting an attacker access to normally-restricted portions of the host's filesystem. This can lead to the disclosure of security-related information, leaving the host open to further compromise.

Connect to a resource using smbclient. 

Issue commands "cd ../" or "cd ..."

相关推荐: Multiple Vendor .BAT/.CMD Remote Command Execution Vulnerability

Multiple Vendor .BAT/.CMD Remote Command Execution Vulnerability 漏洞ID 1105167 漏洞类型 Input Validation Error 发布时间 1996-03-01 更新时间 199…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享