Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Web Application Information DisclosureWeb Application Information Disclosure
Previous
 
Next
New Post
9/17/2012 5:51 AM
 

After the system scanning for security issue,  I get the report and must to fix the risk factor from port 443  as:

443/tcp - Web Application Information Disclosure
Synopsis
The remote web application discloses path information.
Description
At least one web application hosted on the remote web server discloses the physical path to its directories when a malformed request is sent to it.
Leaking this kind of information may help an attacker fine-tune attacks against the application and its backend.
Solution
Filter error messages containing path information.
Plugin Information:
Publication date: 2012/01/25, Modification date: 2012/02/24
Ports
tcp/443
The request POST /Default.aspx HTTP/1.1
Host: intranet.sitetest.com.hk
Accept-Charset: iso-8859-1,utf-8;q=0.9,*;q=0.1
Accept-Language: en
Content-Type: application/x-www-form-urlencoded
Connection: Keep-Alive
Content-Length: 31
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)
Pragma: no-cache
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */*
SelectURL3=Default.aspx%00.html
produces the following path information :
<span id="dnn_dnnCOPYRIGHT_lblCopyright" class="SkinObject">© Sie [...]
&nbsp;&nbsp;|&nbsp;&nbsp;
<a id="dnn_dnnTERMS_hypTerms" class="SkinObject

 

I did the errorpage redirect and clean up the database. That works when I entry any  wrong aspx.
Please advise, Thanks for millions.

 
New Post
9/20/2012 3:19 PM
 
Looking at your error message, unless there is something missing from this post. There is no physical path information displayed as part of that. It appears to be a false positive based on what I can see here.

-Mitchel Sellers
Microsoft MVP, ASPInsider, DNN MVP
CEO/Director of Development - IowaComputerGurus Inc.
LinkedIn Profile

Visit mitchelsellers.com for my mostly DNN Blog and support forum.

Visit IowaComputerGurus.com for free DNN Modules, DNN Performance Tips, DNN Consulting Quotes, and DNN Technical Support Services
 
New Post
10/15/2012 10:53 AM
 

Mitch,

I am having the same problem.  Here is the error I received from security metrics.


Description: Web Application Information Disclosure Synoposis: The remote web application discloses path information. Impact: At least one web application hosted on the remote web server discloses the physical path to its directories when a malformed request is sent to it. Leaking this kind of information may help an attacker fine-tune attacks against the application and its backend. Data Received: The request POST /default.aspx HTTP/1.1\r Host: www.practicepointhiv.com\r Accept-Charset: iso-8859-1,utf-8;q=0.9,*;q=0.1\r Accept-Language: en\r Content-Type: application/x-www-form-urlencoded\r Connection: Keep-Alive\r Content- Length: 79\r User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)\r Pragma: no-cache\r Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */*\r \r dnn$ctr512 $DNNArticle_List$MyArticleList$MyPageNav$dlPages=default.aspx%00.html produces the following path information : <span id="dnn_dnnCopyright_lblCopyright" class="FooterLinks">Copyr [...] &nbsp;&nbsp;&nbsp; <a id="dnn_dnnTerms_hypTerms" class="FooterLinks" rel="nofollow" href="h ttp://www .practicepointhiv.com/Home/tabid/38/ctl/Terms/Default.aspx">Ter ms Of Use</a>&nbsp;&nbsp;&nbsp; <a id="dnn_dnnPrivacy_hypPrivacy" class="FooterLinks" rel="nofollo [...] </div> The request POST /Home/tabid/38/ctl/Privacy/Default.aspx HTTP/1.1\r Host: www.practicepointhiv.com\r Accept-Charset: iso-8859-1,utf-8;q=0.9,*;q=0.1\r Accept-Language: en\r Content-Type: application/x-www-form-urlencoded\r Connection: Keep-Alive\r Content- Length: 44\r User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)\r Pragma: no-cache\r Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */*\r \r dnn$dnnSearch$txtSearch=Default.aspx%00.html produces the following path information : <body id="Body"> <form name="Form" method="post" action="/Home/tabid/38/ctl/Privacy/Defau lt.aspx" id="Form" enctype="multipart/form-data"> <div> <input type="hidden" name="StylesheetManager_TSSM" id="StylesheetM [...] The request POST /Home/tabid/38/ctl/Terms/Default.aspx HTTP/1.1\r Host: www.practicepointhiv.com\r Accept-Charset: iso-8859-1,utf-8;q=0.9,*;q=0.1\r Accept-Language: en\r Content-Type: application/x-www-form-urlencoded\r Connection: Keep-Alive\r Content- Length: 44\r User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)\r Pragma: no-cache\r Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */*\r \r dnn$dnnSearch$txtSearch=Default.aspx%00.html produces the following path information : <body id="Body"> <form name="Form" method="post" action="/Home/tabid/38/ctl/Terms/Default .aspx" id="Form" enctype="multipart/form-data"> <div> <input type="hidden" name="StylesheetManager_TSSM" id="StylesheetM [...] The request POST /Default.aspx HTTP/1.1\r Host: www.practicepointhiv.com\r Accept-Charset: iso-8859-1,utf-8;q=0.9,*;q=0.1\r Accept-Language: en\r Content-Type: application/x-www-form-urlencoded\r Connection: Keep-Alive\r Content- Length: 79\r User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)\r Pragma: no-cache\r Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */*\r \r dnn$ctr512 $DNNArticle_List$MyArticleList$MyPageNav$dlPages=Default.aspx%00.html produces the following path information : <span id="dnn_dnnCopyright_lblCopyright" class="FooterLinks">Copyr [...] &nbsp;&nbsp;&nbsp; <a id="dnn_dnnTerms_hypTerms" class="FooterLinks" rel="nofollow" href="h ttp://www .practicepointhiv.com/Home/tabid/38/ctl/Terms/Default.aspx">Ter ms Of Use</a>&nbsp;&nbsp;&nbsp; <a id="dnn_dnnPrivacy_hypPrivacy" class="FooterLinks" rel="nofollo [...] </div> The request POST /Home.aspx HTTP/1.1\r Host: www.practicepointhiv.com\r Accept-Charset: iso-8859-1,utf-8;q=0.9,*;q=0.1\r Accept-Language: en\r Content-Type: application/x-www-form-urlencoded\r Connection: Keep-Alive\r Content- Length: 76\r User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)\r Pragma: no-cache\r Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */*\r \r dnn$ctr512 $DNNArticle_List$MyArticleList$MyPageNav$dlPages=Home.aspx%00.html produces the following path information : <span id="dnn_dnnCopyright_lblCopyright" class="FooterLinks">Copyr [...] &nbsp;&nbsp;&nbsp; <a id="dnn_dnnTerms_hypTerms" class="FooterLinks" rel="nofollow" href="h ttp://www .practicepointhiv.com/Home/tabid/38/ctl/Terms/Default.aspx">Ter ms Of Use</a>&nbsp;&nbsp;&nbsp; <a id="dnn_dnnPrivacy_hypPrivacy" class="FooterLinks" rel="nofollo [...] </div> Resolution: Filter error messages containing path information.Risk Factor: Medium/ CVSS2 Base Score: 5.0 AV:N/AC:L/Au:N/C:P/I:N/A:N

 
New Post
10/15/2012 3:39 PM
 
Any one with any ideas on this? Anyone still having same issue?
Not able to pass PCI Compliance with css showing path.
 
New Post
10/16/2012 8:06 AM
 
I really need to get this cleaned up. I can't believe no one else has this problem.
 
Previous
 
Next
HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Web Application Information DisclosureWeb Application Information Disclosure


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out