?? 2068.txt
字號(hào):
Rule:--Sid:2068--Summary:This event is generated when an attempt is made to exploit an input handling error in BitKeeper.--Impact:Arbitrary code execution--Detailed Information:BitKeeper is a cross platform commercial application for managing software development.When used in daemon mode, BitKeeper opens a listening service that can be accessed via an ordinary http request. The input from this request is not correctly processed and allows execution of arbitrary code.A proof of concept exploit is available for this vulnerability.--Affected Systems:All versions of BitKeeper up to and including version 3.0 running in daemon mode.--Attack Scenarios:The attacker can send a specially crafted URI to the listening service that contains code the attacker wishes to execute.Proof of concept URI by Maurycy Prodeus:http://www.example.com:port/diffs/foo.c@%27;echo%20%3Eiwashere%27?nav=index.html|src/|hist/foo.c--Ease of Attack:Simple--False Positives:None Known--False Negatives:None Known--Corrective Action:Upgrade to version 3.0.1.Do not run BitKeeper in daemon mode.Disallow all access to the BitKeeper server via http.--Contributors:Sourcefire Vulnerability Research TeamBrian Caswell <bmc@sourcefire.com>Nigel Houghton <nigel.houghton@sourcefire.com>--Additional References:BitKeeper:http://www.bitkeeper.com/--
?? 快捷鍵說明
復(fù)制代碼
Ctrl + C
搜索代碼
Ctrl + F
全屏模式
F11
切換主題
Ctrl + Shift + D
顯示快捷鍵
?
增大字號(hào)
Ctrl + =
減小字號(hào)
Ctrl + -