CGI Alaska

Kurt Seifried discusses security with a focus on CGI scripts. Does you site-or your ISP's-have CGI scripts that are a security risk?

Local Companies

Surveyors Exchange Co
800-770-5500
3695 Springer St
Anchorage, AK
Taskklock
907-677-8963
1115 Whitney RD
Anchorage, AK
GFI Software
919-379-3361
15300 Weston Parkway
Cary, AK
Ctg
907-261-6500
4701 Business Park Blvd
Anchorage, AK
Apex Logic
907-274-6696
1343 G St
Anchorage, AK
Accoladde
+91 9962299053
2033 Gateway place
San Jose, AK
SDAC Inc. [Strategic Data Alliance Consulting, Inc.]
407-367-9510
583 Caledonia Place
Sanford, AK
Communications Software Inc
907-279-7800
1505 W 32nd Ave
Anchorage, AK
PKWARE, Inc.
414-289-9788 ext 117
648 N Plankinton Ave
Milwaukee, AK
Alaska Computer Brokers
907-267-4200
551 W Dimond Blvd
Anchorage, AK

provided by: 
Originally published at Internet.com


By Kurt Seifried (seifried@securityportal.com) for Security Portal -----------------------------------

I was surfing on the Web a few days ago looking at various homepages for security professionals to see if there were any interesting links. I discovered nothing too interesting, so, being bored, I hit a link to a page with various network utilities available through cgi interfaces.

One did catch my interest, a DNS zone transfer utility online, so I plugged in one of my domains. It tried to transfer it and failed. Being somewhat disappointed, I went to get a delicious, refreshing Diet Pepsi [1]. Coming back to the computer, I thought "Hmm. Well since I won't be able to transfer domains that are properly secured, and transferring domains that aren't secure isn't really interesting either, what can I do?"

It occurred to me to ask which domains might the server this cgi is hosted on be allowed to transfer (since it was a WWW server at a major European ISP). So, I tried to transfer the DNS zone for the ISP, which worked. Interesting, I thought, but not too interesting, so I wrote a script to use their CGI script to grab all their subdomains. Now this was interesting: 90+ subdomains, quite a few of which were very "interesting" (noc.*). Also, you could transfer any domain they hosted, which is an interesting fact, considering they host several tens of thousands of domains. I then emailed the company to tell them about the problem, and haven't yet heard back from them...

Read article at Internet.com site

Featured Local Company

Accoladde

+91 9962299053
2033 Gateway place
San Jose, AK
http://www.accoladde.com


Topics: 
Architecture & Design Languages & Tools Project Management Web Services
Database Microsoft & .NET Security Wireless
Java Open Source Techniques XML