Short Name |
SCAN:MISC:HTTP:VIOLATION-ACCS |
---|---|
Severity |
Info |
Recommended |
No |
Category |
SCAN |
Keywords |
PHP |
Release Date |
2003/04/22 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to access the vulnerable violation.php3 script in Phorum, a free, open source forum/discussion package for Web sites. Attackers can send maliciously crafted URL requests to violation.php3 to arbitrarily relay e-mail through the host MTA.
Phorum is a freely available, open source package originally written by Brian Moon. The package is designed to add enhanced features to a web page, allowing users to interact through bulletin board style chats forums and discussions. A problem with the Phorum package could allow remote users to arbitrarily relay email. Due to the way violation.php3 handles URL's as arguments, it is possible to create a custom crafted URL request to the script which will allow a remote user to send email through the hosts MTA. This email will then be delivered to the specified person with the appearance of coming from the web host. This problem makes it possible for a user with malicious intentions to socially engineer, mailbomb, or spam from the web host, and potentially get the host blacklisted in one of such lists.