Archives for: March 2008
Saturday, Mar 29th, 2008
Balupton.com | Upcoming
I’ve done up the base of my new site here: http://www.balupton.com/home/
Feel free to leave any feedback you can.
Wednesday, Mar 05th, 2008
WebCT 4.x Javscript Session Stealer Exploits
WebCT 4.x Javascript Session Stealer Exploits
Software: WebCT Campus Edition 4.x (http://secunia.com/product/3280/)
Affected Version: 4.1.5.8
Discoverer: Benjamin “balupton” Lupton
Date Discovered: November 2005
Date Reported: 25/06/2007
Software Author Contacted (again) on: 20/07/2007
Date Published: 05/03/2008
Published At:
http://www.balupton.com/blogs/dev?title=webct_session_stealer_exploit
http://www.balupton.com/documents/webct_exploits.txt
http://seclists.org/fulldisclosure/2008/Mar/0051.html
http://www.securityfocus.com/bid/28107/info
http://secwatch.org/advisories/1020585/
http://secunia.com/advisories/29227/
Attack Type:
Javascript Session Stealer Exploit.
Description:
Mail & Discussion Board messages are not properly checked for javascript, allowing javascript to perform a session stealing attack (allowing the attacker to be logged in as the victim).
Tested On:
Attacks were tested fully on eCentral TAFE’s WebCT System in November 2005 (with permission of staff),
and again on Curtin University’s WebCT System in June 2006 (but this time only to see if the javascript will run).
Action Taken:
Contacted TAFE lecturers and administrators, who didn’t really care.
Contacted WestOne multiple times, but never recieved any response.
Then contacted Secunia, which would not publish as the discoverer did not own their own copy of the software in question.
Published as WebCT is being phased out, with Blackboard being the replacement.
Steps:
…
Read the full report here: http://www.balupton.com/documents/webct_exploits.txt