Re: Fixing URL redirect exploit at /exchweb/bin/auth/owaauth.dll

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



I tried the fix you mentioned below but it does not work in our case. This is because the McAfee ScanAlert PCI scanner uses a form builder that is directly POSTing to https://<myserver>/exchweb/bin/auth/owaauth.dll using, among others, a parameter 'destination' pointing to the redirected URL. So changing logon.asp does nothing in that case since this exploit is directly hitting owaauth.dll.

Based on what I've read here and the link posted by Chris, there appears to be no fix except to restrict by IP. In my case I'll just turn off OWA since nobody is using it currently. That's a luxury that other companies can't afford.

At this poing I'm appealing to ScanAlert to mark this as a false positive as I read that others had success with that route.
Hello!

What happens if you make up your own redirect and test it against your
client's server?

Thinking that I actually understand the exploit, I did this test:

https://mail.mySBSserver.net/exchweb/bin/auth/owalogon.asp?url=http://
www.yahoo.com

I expected it to end up at www.yahoo.com, but it just went to my OWA
on my server.

I have Forms Based Authentication enabled on my SBS and on my clients'
systems, and attempting to use the exploit does NOT redirect. It goes
to OWA on the appropriate servers.

I also found this workaround in a Google search.

http://osvdb.org/show/osvdb/13621

Does that help?

Gregg Hill

"Chris" <Chris@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:B459EFD6-1C7A-4939-B382-39C285DCA3FD@xxxxxxxxxxxxxxxx

Hi,
I had the same issue with the same company a few months ago. I
didn't
resolve it either even after a support case with microsoft. Their
verdict
was that the file was doing it's job and was not a vulnerability.
The
only
technical soltuions are to disable OWA or use Forms Based
Authentication
but
the latter is not a good solution.
I opened a forum post when I had the issue:
http://forums.microsoft.com/TechNet/showpost.aspx?postid=3304653&site
id=17
Otherwise, maybe move SQL databases (assuming SBS Premium) to another
server
and this can help with PCI, however, strictly speaking (4.2 I think)
says
you
can't have multiple roles on the server which kinda rules out SBS
anyway!!!
Hope you have more success.
Regards
"Jason" wrote:

We recently migrated to SBS 2003 and over the weekend we ran our
McAfee
ScanAlert
PCI compliance scan on the server. The scan picked up the "User
specified
URL redirection (Open Redirect)" vulnerability in OWA which I'm sure
some
of you know about. Details on it are here
http://www.exploitlabs.com/files/advisories/EXPL-A-2005-001-owa.txt.
I'm very worried since this has been reported since 2005 and there
appears
to be no fix. As a retail company we must maintain PCI compliance.
This
vulnerability
is a level 3 (HIGH) and must be fixed by next quarter or we will
fail PCI
compliance and face potentially huge fines. Does anyone know of a
fix to
this issue?
I was thinking we could rename the exchweb path to something obscure
but that does not appear to be an option.



.



Relevant Pages

  • Re: Fixing URL redirect exploit at /exchweb/bin/auth/owaauth.dll
    ... can be fixed by hard-coding the redirect to your server external IP/domain ... logon.asp) and can be accessed directly from the internet of an OWA server. ... PCI is virtually impossible. ...
    (microsoft.public.windows.server.sbs)
  • Re: OWA display is messed up...
    ... need to install anyway, ... and I could browse to and log into the OWA. ... I'm not sure how relevant the WINS server ... now it's back to trying to fix the display of the OWA. ...
    (microsoft.public.backoffice.smallbiz)
  • Re: OWA display is messed up...
    ... I have applied the Gzip fix, and still> have OWA display problem. ... TGhe left side of the OWA screen looks fine> but the entire right frame is solid white. ... I'm not sure if I want to apply a major> service pack when logged into the server via Terminal Server session. ... >> need to install anyway, ...
    (microsoft.public.backoffice.smallbiz)
  • Re: OWA display is messed up...
    ... I have applied the Gzip fix, ... TGhe left side of the OWA screen looks fine ... service pack when logged into the server via Terminal Server session. ... now it's back to trying to fix the display of the OWA. ...
    (microsoft.public.backoffice.smallbiz)
  • Re: OWA Email Display Issues
    ... 831464 FIX: IIS 6.0 Gzip Compression Corruption Causes Access Violations ... Clear the IIS server files follow these steps: ... The fix allows you to enable GNU zip > compression using the Exchange System Manager for> Microsoft Exchange Server 2003. ... Why would enabling Gzip fix my OWA display issue? ...
    (microsoft.public.windows.server.sbs)