Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 12-29-2011, 09:34 AM
New Member
 
Posts: 4
Default Potential Information Disclosure or Privilege Escalation in CGI

We have a third-party who scans our network for compliance and they used Nessus to find the following vulnerability. Any idea how to correct this?

Threat ID: 144134

THREAT REFERENCE

Summary:
Potential Information Disclosure or Privilege Escalation in CGI

Risk: Critical (4)
Type: Nessus
Port: 443
Protocol: TCP
Threat ID: 144134

Information From Target:
Using the GET HTTP method, Nessus found that :

+ The following resources may be vulnerable to unseen parameters :

/zimbra/css/common,login,zhtml.css?skin=&v=&debug=1

-------- output --------
P,TH,TD,DIV,SELECT,INPUT[type=text],INPUT[type=password],INPUT[typ [...]
P,TH,TD,DIV,SELECT,INPUT,TEXTAREA,BUTTON{font-family:"Helvetica Ne [...]
HTML{width:100%;height:100%;}
-------- vs --------
/*
* #define WINDOWS true
* #define MSIE_5_5_OR_HIGHER true
------------------------

Solution:


Inspect the reported CGIs and, if necessary, modify them so that
security is not based on obscurity.

Details:
By sending requests with additional parameters such as 'admin', 'debug', or 'test' to CGI scripts hosted on the remote web server, Nessus was able to generate at least one significantly different response even though the parameters themselves do not actually appear in responses.

This behavior suggests that such a parameter, while unseen, are used by the affected application(s) and may enable an attacker to bypass authentication, read confidential data (like the source of the scripts), modify the behavior of the application(s) or conduct similar attacks to gain privileges.

Note that this script is experimental and may be prone to false positives.
Reply With Quote
  #2 (permalink)  
Old 12-29-2011, 09:49 AM
Zimbra Consultant & Moderator
 
Posts: 20,314
Default

Quote:
Originally Posted by PastorOfMuppets View Post
We have a third-party who scans our network for compliance and they used Nessus to find the following vulnerability.
Why not start by updating your forum profile with the output of the following command:
Code:
zmcontrol -v
__________________
Regards


Bill
Reply With Quote
  #3 (permalink)  
Old 12-29-2011, 10:10 AM
New Member
 
Posts: 4
Default

Quote:
Originally Posted by phoenix View Post
Why not start by updating your forum profile with the output of the following command:
Code:
zmcontrol -v
Release 7.1.3_GA_3346.RHEL5_64_20110928134520 CentOS5_64 FOSS edition, Patch 7.1.3_P1.
Reply With Quote
  #4 (permalink)  
Old 12-29-2011, 10:30 AM
New Member
 
Posts: 4
Default

I just contacted the third-party who is scanning us and they said we just need to turn debugging off so the output won't be different. Does anyone know the CLI command? I'm going to try and google it and find out.

Thanks.
Reply With Quote
  #5 (permalink)  
Old 04-23-2012, 08:54 PM
Starter Member
 
Posts: 1
Default

Did you ever find a resolution for this one? I'm also trying to disable it.

$ zmprov gacf | grep -i debug
zimbraHttpDebugHandlerEnabled: TRUE

$ zmprov gs `zmhostname` zimbraHttpDebugHandlerEnabled
# name mail.domain.com
zimbraHttpDebugHandlerEnabled: TRUE

I tried setting both of those to FALSE and restarting but it had no effect on the /zimbra/css/common,login,zhtml.css?debug=1 query string results.

Thanks.
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.