CGI Louisiana

Kurt Seifried discusses security with a focus on CGI scripts. Does you site-or your ISP's-have CGI scripts that are a security risk?

Local Companies

Quasar Software Inc
504-485-5606
710 Weiblen Pl
New Orleans, LA
Ecad Inc
504-818-3091
824 Elmwood Park Blvd
New Orleans, LA
Creative Computer Solutions
225-925-3210
1651 Thibodeaux Ave
Baton Rouge, LA
Network Solution Providers
225-709-2591
5515 Superior Dr
Baton Rouge, LA
Cyrious Software
225-752-2867
12627 Jefferson Hwy
Baton Rouge, LA
VanillaSoft, Inc.
866-763-8826
1820 St. Charles Ave.
New Orleans, LA
Electronic Evidence Retrival LLC
504-483-0201
718 N Alexander St
New Orleans, LA
CMA Technology Solutions
225-927-9200
8180 YMCA Plaza DR
Baton Rouge, LA
Custom Accounting Solutions Inc
225-935-2202
2974 Fritchie Dr
Baton Rouge, LA
Bits Technical Corp
225-752-8899
14141 Airline Hwy
Baton Rouge, LA

provided by: 
Originally published at Internet.com


By Kurt Seifried (seifried@securityportal.com) for Security Portal -----------------------------------

I was surfing on the Web a few days ago looking at various homepages for security professionals to see if there were any interesting links. I discovered nothing too interesting, so, being bored, I hit a link to a page with various network utilities available through cgi interfaces.

One did catch my interest, a DNS zone transfer utility online, so I plugged in one of my domains. It tried to transfer it and failed. Being somewhat disappointed, I went to get a delicious, refreshing Diet Pepsi [1]. Coming back to the computer, I thought "Hmm. Well since I won't be able to transfer domains that are properly secured, and transferring domains that aren't secure isn't really interesting either, what can I do?"

It occurred to me to ask which domains might the server this cgi is hosted on be allowed to transfer (since it was a WWW server at a major European ISP). So, I tried to transfer the DNS zone for the ISP, which worked. Interesting, I thought, but not too interesting, so I wrote a script to use their CGI script to grab all their subdomains. Now this was interesting: 90+ subdomains, quite a few of which were very "interesting" (noc.*). Also, you could transfer any domain they hosted, which is an interesting fact, considering they host several tens of thousands of domains. I then emailed the company to tell them about the problem, and haven't yet heard back from them...

Read article at Internet.com site

Featured Local Company

VanillaSoft, Inc.

866-763-8826
1820 St. Charles Ave.
New Orleans, LA
http://www.vanillasoft.com

Related Local Event
Annual Technical Conference & Exhibition (ATCE 2009)
Dates: 10/4/2009 - 10/7/2009
Location: Ernest N Morial Convention Center, New Orleans
New Orleans, LA
View Details

Topics: 
Architecture & Design Languages & Tools Project Management Web Services
Database Microsoft & .NET Security Wireless
Java Open Source Techniques XML