Microsoft Commerce Server 2002:
Logon as known user with a false password
Windows Server 2000/2003
+ Internet Information Server 5/6
+ Commerce Server 2002
Microsoft Commerce Server is used by company's who want to give customers
the opportunity to change there own details on the internet or buying
Company's who use it are: eCommerce site's or interactive company's
The problem lays in the sample files of "authfiles". If you make your own
Solution site in Commerce Server and the "authfiles" are installed on your
server, you're vulnerable for positive user logon's using false passwords.
If you know a user (some site's uses a e-mail address) and you go to
http://site/authfiles/login.asp (some site's has it in an other directory)
and you enter the Username and a false password you get a error.
After the error's you go with the same browser to the directory root of the
site http://site/ You get an other error and if you go again to the site and
you are logon as the entered user.
Vendor Response time:
31-03-2003 - First contact
26-08-2003 - Fixed in SP2
Fixed by Microsoft
Download & Install Service Pack 2:
-- Quote Readme.htm --
A fix for a security issue reported by Dimitri van de Giessen
-- End Quote Readme.htm --
Also they already made a warning before Service Pack 2 came:
-- Quote Microsoft --
Solution Sites AuthFiles Folder: Remove Directory
The Solution Sites include a folder called AuthFiles. You can use the files
in this folder if you want to integrate AuthFilter into your site.
If you do not want to use AuthFilter, you must remove the AuthFiles
directory or remove the permissions from the directory. If you do not, your
site will be a security risk.
-- End Quote Microsoft --.
Dimitri van de Giessen
E-mail d.vd.giessen (at) xs4all (dot) nl [email concealed]
Tel. number: +31622607367 (The Netherlands)