{"id":372,"date":"2011-06-13T19:19:23","date_gmt":"2011-06-14T01:19:23","guid":{"rendered":"http:\/\/www.foofus.net\/?page_id=372"},"modified":"2011-06-13T19:19:23","modified_gmt":"2011-06-14T01:19:23","slug":"javascript-injection-in-microsoft-lync","status":"publish","type":"page","link":"http:\/\/h.foofus.net\/?page_id=372","title":{"rendered":"Javascript Injection in Microsoft Lync"},"content":{"rendered":"<p>============================================================================<br \/>\nFoofus.net Security Advisory: foofus-20110610<br \/>\n============================================================================<br \/>\nTitle:\t\tJavascript Injection in Microsoft Lync<br \/>\nVersion:\t4.0.7577.0<br \/>\nVendor:\t\tMicrosoft<br \/>\nRelease Date:\t2010-06-10<br \/>\nIssue Status:\tFix available<br \/>\n============================================================================<\/p>\n<p>1. Summary<\/p>\n<p>Microsoft Lync version 4.0.7577.0 is vulnerable to a javascript injection<br \/>\nvulnerability.<\/p>\n<p>2. Description<\/p>\n<p>Javascript commands can be stacked within the url in the &#8220;reachLocale&#8221;<br \/>\nvariable in ReachJoin.aspx.  Arbitrary javascript can be inserted, with<br \/>\nsome restrictions (notably that characters such as &#8220;&gt;&#8221; will invoke .NET<br \/>\nsecurity protections and cause the page to fail to display)<\/p>\n<p>3. Proof of Concept<\/p>\n<p>The following URL will load an image in a new window or tab, as well as<br \/>\ndisplay an alert with arbitrary content:<\/p>\n<p>https:\/\/[target]\/Reach\/Client\/WebPages\/ReachJoin.aspx?xml=&#038;&#038;reachLocale<br \/>\n=en-us%22;var%20xxx=%22http:\/\/www.foofus.net\/~bede\/foofuslogo.jpg%22;<br \/>\nopen%28xxx%29;alert28%22error,%20please%20enable%20popups%20from<br \/>\n%20this%20server%20and%20reload%20from%20the%20link%20you%20were<br \/>\n%20given%22%29\/\/<\/p>\n<p>Pop-ups will need to be enabled in order to load a new tab, but this can be<br \/>\ncircumvented by social engineering (i.e. a dialog box) or possibly by more<br \/>\nclever javascript insertion.<\/p>\n<p>4. Impact<\/p>\n<p>Exploiting this attack allows an adversary to inject most types of<br \/>\nJavascript into the page and in order to execute client-side attacks or<br \/>\nperform social engineering attacks.  These attacks can easily be manipulated<br \/>\nto compromise a target workstation.<\/p>\n<p>5. Affected Products<\/p>\n<p>Only version 4.0.7577.0 has been tested.  This vulnerability may exist in<br \/>\nother versions.<\/p>\n<p>6. Solution<\/p>\n<p>According to Microsoft, the vulnerability can be resolved by updating with<br \/>\nthe &#8220;update package for Lync Server 2010, Web Components Server: April 2011&#8221;<br \/>\nat http:\/\/support.microsoft.com\/kb\/2500441<\/p>\n<p>7.  Timetable<\/p>\n<p>2011-05-31  Advisory written and submitted to Microsoft<br \/>\n2011-05-31  Vendor confirms receipt of advisory<br \/>\n2011-06-10  Vendor confirms vulnerability, advises availability of patch<br \/>\n2011-06-10  Disclosure<\/p>\n<p>8.  Reference<\/p>\n<p>http:\/\/www.foofus.net\/?p=363<\/p>\n<p>9.  Credits<\/p>\n<p>bede@foofus.net (Mark Lachniet)<\/p>\n","protected":false},"excerpt":{"rendered":"<p>============================================================================ Foofus.net Security Advisory: foofus-20110610 ============================================================================ Title: Javascript Injection in Microsoft Lync Version: 4.0.7577.0 Vendor: Microsoft Release Date: 2010-06-10 Issue Status: Fix available ============================================================================ 1. Summary Microsoft Lync version 4.0.7577.0 is vulnerable to a javascript injection vulnerability. 2. Description Javascript commands can be stacked within the url in the &#8220;reachLocale&#8221; variable in ReachJoin.aspx. Arbitrary javascript [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":0,"parent":273,"menu_order":0,"comment_status":"open","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-372","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"http:\/\/h.foofus.net\/index.php?rest_route=\/wp\/v2\/pages\/372","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/h.foofus.net\/index.php?rest_route=\/wp\/v2\/pages"}],"about":[{"href":"http:\/\/h.foofus.net\/index.php?rest_route=\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"http:\/\/h.foofus.net\/index.php?rest_route=\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"http:\/\/h.foofus.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=372"}],"version-history":[{"count":0,"href":"http:\/\/h.foofus.net\/index.php?rest_route=\/wp\/v2\/pages\/372\/revisions"}],"up":[{"embeddable":true,"href":"http:\/\/h.foofus.net\/index.php?rest_route=\/wp\/v2\/pages\/273"}],"wp:attachment":[{"href":"http:\/\/h.foofus.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=372"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}