Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 6 of 6
  1. #1
    Member
    Join Date
    Jan 2007
    Posts
    9

    Question SecurityMetrics issue with webmail login page

    A client of mine is having problems getting SecurityMetrics to pass their PCI DSS scan because of an alleged issue with the webmail login page.

    The issue was initially detected as an insecure version of HP Openview running on the server due to the url http://www.domain.name:2095/OvCgi/co...pl?node=a\x7cw returning a response.

    After a few emails back and fourth SecurityMetrics recognised that HP Openview was not installed, but said that the issue was that the webmail login form was including the request url in a hidden 'goto_url' field in the login form, which 'may not be' sanatised.

    Below is their email regarding the issue - any help on this would be appreciated. Is this really a problem or just another false positive from SecurityMetrics? These guys and indeed the whole PCI DSS compliance system are causing me and many of my clients a massive headache. Is it just me?!


    ----

    Mr X,

    The issues isn't necessarily with HP Openview, it is that the way the server is responding is commonly an HP error, but in their case it's a problem with WebMail. I looked into this with my supervisor and we found the following:

    <body>
    <div id="wrap">
    <div id="top-mail"></div>
    <div id="mid">
    <div id="content-wrap" align="center">
    <form action="/login/" method="post" >
    <input type="hidden" name="login_theme" value="cpanel" />
    <table width="200" class="login" cellpadding="0" cellspacing="0">
    <tr>
    <td align="left"><b>Login</b></td>
    <td>&nbsp;</td>
    </tr>
    <tr>
    <td class="login_lines">Email:</td>
    <td class="login_lines"><input type="text" tabindex="1" id="user" name="user" size="16" /></td>
    </tr>
    <tr class="row2">
    <td class="login_lines">Password:</td>
    <td class="login_lines"><input type="password" tabindex="2" id="pass" name="pass" size="16" /></td>
    </tr>
    <tr>
    <td colspan="2" style="text-align: center"><input type="submit" tabindex="3" id="login" value="Login" class="input-button" /></td>
    </tr>
    </table>
    <input type="hidden" name="goto_uri" value="/OvCgi/connectedNodes.ovpl?node=a\x7cw" />
    </form>

    That last input type line includes a hidden form that has the value of "/OvCgi/connectedNodes.ovpl" which was probably from our original GET request, as shown here:
    Code:
    $ telnet http://www.domain.tld 2095
    Trying 123.123.x.x...
    Connected to http://www.domain.tld.
    Escape character is '^]'.
    GET /OvCgi/connectedNodes.ovpl?node=a\x7cw HTTP/1.0
    Host: http://www.domain.tld:2095
    User-Agent: Mozilla/4.0
    Connection: Keep-alive
    Their page may not be sanitizing the user-supplied input, which would cause this to flag. I would see if there is an update from cPanel that may fix issue.

    ---

  2. #2
    Member
    Join Date
    Jan 2007
    Posts
    9

    Default Re: SecurityMetrics issue with webmail login page

    Any ideas on this one? The client can't pass the SecurityMetrics scan until it is resolved... and SM keep saying to talk to cPanel as it's a bug in cPanel...

  3. #3
    Member twhiting9275's Avatar
    Join Date
    Sep 2002
    Posts
    366
    cPanel/Enkompass Access Level

    Root Administrator

    Default Re: SecurityMetrics issue with webmail login page

    Quote Originally Posted by Wheeler View Post
    Any ideas on this one? The client can't pass the SecurityMetrics scan until it is resolved... and SM keep saying to talk to cPanel as it's a bug in cPanel...
    Solution? Don't use Security Metrics. They're a major PITA when dealing with things.
    Unfortunately, you're going to probably have the same problem with any provider, though scanalert (Mcaffee) will at least listen to what you have to say and in cases like this remove the problematic alert from you. SecurityMetrics won't.

    Every PCI provider is different in how they test, and grade things, which is why, at this point in time PCI compliance is nothing but a joke.
    Linux Tech Networks: Reliable Server Administration and Monitoring since 2002

  4. #4
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Sep 2007
    Posts
    139

    Default Re: SecurityMetrics issue with webmail login page

    Do you have the CVE number?

  5. #5
    Member
    Join Date
    Jan 2007
    Posts
    9

    Default Re: SecurityMetrics issue with webmail login page

    The CVE number from the scan results is 2005-2773 - which relates to HP OpenView. I've asked if there is a separate CVE number for the issue relating to the webmail login, which is what they say is causing the HP OpenView (CVE-2005-2773) issue to flag, and will post it here once they respond.

    Thanks for the help so far

  6. #6
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Sep 2007
    Posts
    139

    Default Re: SecurityMetrics issue with webmail login page

    According to the CVE, the actual problem with the hp openview is that part of the url is used as parameters for a system() call. This is not the case with webmail. Cpanel uses this parameter to redirect to that page after you login. Beyond maybe getting redirected to a not found page, I don't really think it would be a big deal. It defiantly does not use the parameters for some hidden system call. I've generally been able to just tell some scanning companies it is a false positive since we are not using hp openview and it gets accepted.

Similar Threads & Tags
Similar threads

  1. Webmail login page and customize webmail server installation
    By patelbhavin8008 in forum E-mail Discussions
    Replies: 2
    Last Post: 05-25-2011, 05:22 AM
  2. Webmail login page and autoload
    By iLLuSi0nS in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 06-12-2008, 01:37 PM
  3. Webmail login page not working.
    By Big Gorilla in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 06-12-2007, 07:50 AM
  4. webmail login page
    By yukonn in forum New User Questions
    Replies: 1
    Last Post: 01-27-2006, 03:15 AM
  5. Change Webmail Login Page?
    By warwickhunt in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 10-24-2003, 02:06 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube