BitDefender – Unauthorized Remote File Access Vulnerability

Today I published an advisory for the BitDefender Update Server. BitDefender is one of the larger vendors for Antivirus software.

The update servers function is to deliver new Antivirus patterns and engine updates to the software clients. Therefore it is using the http protocol and a http daemon. The daemon does not require authentication and is vulnerable to the oldest vulnerability known for webservers: The directory traversal attack.

This means everyone who is able to connect to the port of the Update Server with his webbrowser, is able to read all files on the server (at least on the same partition/drive), including Windows configuration files, password files etc., etc.

It also seems, that BitDefender does not have a dedicated response team, responsible for vulnerabilities within their own products. The mail I send to them, in order to inform them about their vulnerability was responded by an automated mail, requesting me to register on their website in order to access their support material…… sorry guys, i dont have time for such games…. please learn how other AV- and Softwarevendors are handling this!!!

You can find the original advisory here.

More of my humble advisories can be found on my website….

21 Responses to “BitDefender – Unauthorized Remote File Access Vulnerability”

  1. xaitax sagt:

    Toter Link.
    Bitte um Berichtigung, will ihn/es ja lesen. :)

  2. oliver.karow sagt:

    Muss das erstmal hochladen… bin nicht so gut am computer, daher dauert das etwas länger.

    Aber die Zusammenfassung ist die: Lade dir irgendeine Enterprise Software von Bitdefender runter, installiere Sie, aktiviere den Update Server und mache dann ein: echo -e “GET /../../boot.ini HTTP/1.0\r\n\r\n” | nc host port

    PS: Ich versuche mal im laufe des WE das advisory hochzuladen!

  3. torrent UMPlayer…

    BitDefender – Unauthorized Remote File Access Vulnerability « Oliver’s Blog…

  4. minecraft for free…

    BitDefender – Unauthorized Remote File Access Vulnerability « Oliver’s Blog…

  5. torrents WebcamMax…

    BitDefender – Unauthorized Remote File Access Vulnerability « Oliver’s Blog…

  6. torrents Internet Download Manager…

    BitDefender – Unauthorized Remote File Access Vulnerability « Oliver’s Blog…

  7. torrent download WinZip…

    BitDefender – Unauthorized Remote File Access Vulnerability « Oliver’s Blog…

  8. torrent Easeus Partition Master Home Edition…

    BitDefender – Unauthorized Remote File Access Vulnerability « Oliver’s Blog…

  9. torrent download GOM Media Player…

    BitDefender – Unauthorized Remote File Access Vulnerability « Oliver’s Blog…

  10. torrents cracked Free CUDA Video Converter…

    BitDefender – Unauthorized Remote File Access Vulnerability « Oliver’s Blog…

  11. torrent download UMPlayer…

    BitDefender – Unauthorized Remote File Access Vulnerability « Oliver’s Blog…

  12. torrent KMPlayer…

    BitDefender – Unauthorized Remote File Access Vulnerability « Oliver’s Blog…

  13. torrents cracked KMPlayer…

    BitDefender – Unauthorized Remote File Access Vulnerability « Oliver’s Blog…

  14. torrents Skype…

    BitDefender – Unauthorized Remote File Access Vulnerability « Oliver’s Blog…

  15. torrents Advanced SystemCare…

    BitDefender – Unauthorized Remote File Access Vulnerability « Oliver’s Blog…

  16. torrents Avast Free Antivirus…

    BitDefender – Unauthorized Remote File Access Vulnerability « Oliver’s Blog…

  17. torrents RealPlayer…

    BitDefender – Unauthorized Remote File Access Vulnerability « Oliver’s Blog…

  18. torrent Start Menu 8…

    BitDefender – Unauthorized Remote File Access Vulnerability « Oliver’s Blog…

  19. torrent Total Video Converter…

    BitDefender – Unauthorized Remote File Access Vulnerability « Oliver’s Blog…

  20. lawrence crane enterprises…

    BitDefender – Unauthorized Remote File Access Vulnerability « Oliver’s Blog…

  21. video=xmrr8o sagt:

    video=xmrr8o…

    BitDefender – Unauthorized Remote File Access Vulnerability « Oliver’s Blog…