CGI Nevada

Kurt Seifried discusses security with a focus on CGI scripts. Does you site-or your ISP's-have CGI scripts that are a security risk?

Local Companies

Rentex Inc
(800)3044819
3585 E Patrick Ln Ste 1200
Las Vegas, NV
Check Point Software
(702) 633-7778
823 Vineyard Vine Way
North Las Vegas, NV
Intertech Computers
(702)4534433
3321 Sunrise Ave Ste 105
Las Vegas, NV
Conrad & Company
(702) 699-9034
5101 Tropical Rain St
North Las Vegas, NV
RetailSystems, Inc.
(702)6170427
346 Pleasant Summit Dr
Henderson, NV
Janalent
(888)2904870
3291 E Warm Springs Rd Ste 300
Las Vegas, NV
Sparkplug
(702)5058094
3744 Civic Center Dr
N Las Vegas, NV
IT Dev, Inc.
(888)3330477
3365 E Flamingo Rd Ste 5
Henderson, NV
Akers & Associates, Inc.
(702)8662316
720 S 4th St Ste 305
Las Vegas, NV
P.O. Interests, Inc.
(702)8963822
2628 Langford Ave
Las Vegas, NV

provided by: 
Originally published at Internet.com


By Kurt Seifried (seifried@securityportal.com) for Security Portal -----------------------------------

I was surfing on the Web a few days ago looking at various homepages for security professionals to see if there were any interesting links. I discovered nothing too interesting, so, being bored, I hit a link to a page with various network utilities available through cgi interfaces.

One did catch my interest, a DNS zone transfer utility online, so I plugged in one of my domains. It tried to transfer it and failed. Being somewhat disappointed, I went to get a delicious, refreshing Diet Pepsi [1]. Coming back to the computer, I thought "Hmm. Well since I won't be able to transfer domains that are properly secured, and transferring domains that aren't secure isn't really interesting either, what can I do?"

It occurred to me to ask which domains might the server this cgi is hosted on be allowed to transfer (since it was a WWW server at a major European ISP). So, I tried to transfer the DNS zone for the ISP, which worked. Interesting, I thought, but not too interesting, so I wrote a script to use their CGI script to grab all their subdomains. Now this was interesting: 90+ subdomains, quite a few of which were very "interesting" (noc.*). Also, you could transfer any domain they hosted, which is an interesting fact, considering they host several tens of thousands of domains. I then emailed the company to tell them about the problem, and haven't yet heard back from them...

Read article at Internet.com site

Featured Local Company

Janalent

(888)2904870
3291 E Warm Springs Rd Ste 300
Las Vegas, NV

Related Local Events
Northern Nevada Regional Business & Tech Show
Dates: 10/16/2020 - 10/16/2020
Location: .A. Nugget, Sparks
Sparks, NV
View Details

2010 7th IEEE Consumer Communications and Networking Conference (CCNC)
Dates: 1/10/2010 - 1/12/2010
Location: Harrahs Las Vegas Hotel and Casino
Las Vegas, NV
View Details

POWER-GEN International 2009
Dates: 12/8/2009 - 12/10/2009
Location: Las Vegas Convention Center
Las Vegas, NV
View Details

Mobile Business Expo
Dates: 11/16/2009 - 11/20/2009
Location: Mandalay Bay Resort & Casino Convention Center
Las Vegas, NV
View Details

International Telemetering Conference
Dates: 10/26/2009 - 10/29/2009
Location: Riviera Hotel & Conference Center, Las Vegas
Las Vegas, NV
View Details

Topics: 
Architecture & Design Languages & Tools Project Management Web Services
Database Microsoft & .NET Security Wireless
Java Open Source Techniques XML