Microsoft Site Server Information Disclosure

Published on 02 Jul 2018
1 min read
Vulnerability

Data handling is a major responsibility for a web application. The data processed by the application might include sensitive information like user details, credentials, product functionality and many more. There are many servers running on Microsoft site server have major vulnerabilities through which an attacker can access various administrative pages with an unprivileged non-administrative server access. These administrator pages contain sensitive information, if going to wrong hands can completely compromise the application. Microsoft Site Server 3.0 prior to Service Pack 4 installs a default user on the web server named LDAP_Anonymous and password LdapPassword_1. A remote attacker can use these credentials to log into the server locally. Using these credentials, the attacker can perform any actions on the server without leaving any trail. The password for LDAP_Anonymous is hardcoded into the \winnt\system32\pNmsrvs.dll and \winnt\system32\inetsrv\dscomobj.dll. Thus, changing the password through the registry setting has no effect. After logging out, the system automatically removes all traces of its use in LDAP_Anonymous account.

The sensitive files that can be leaked using this vulnerability are:-

  • /SiteServer/Admin/knowledge/persmbr/vs.asp
  • /SiteServer/Admin/knowledge/persmbr/VsTmPr.asp
  • /SiteServer/Admin/knowledge/persmbr/VsLsLpRd.asp
  • /SiteServer/Admin/knowledge/persmbr/VsPrAuoEd.asp

Impact

Using this vulnerability, an attacker can:-

  • get unprivileged access to the server.
  • steal sensitive information about the application.

Mitigation / Precaution

Beagle recommends the following fixes:-

  • Install the latest patch by Microsoft for fixing this vulnerability.
Febna V M
Written by
Cyber Security Engineer

Febna once spent an entire evening arguing with an AI chatbot just to prove that machines can be confidently wrong. The debate ended with no clear winner, but it did spark her curiosity for the fascinating world of artificial intelligence. Today, she works at the intersection of AI and cybersecurity, helping build smarter systems while making sure they don’t become too smart for their own good. When she’s not exploring the future of technology, she’s probably asking “but what if?” one more time.

Experience the Beagle Security platform
Unlock one full penetration test and all Advanced plan features free for 14 days
4.8 on G2 • ISO 27001 certified
See How Beagle Security Works
No credit card • No setup required
Launch interactive demo