ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Excite owns up to gaping EWS security hole

Craig Paterson ZDNet.co.uk

Published: 15 Jan 1998 11:48 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The EWS system is available from Excite as unsupported software that Web site adminstrators can install on their sites to provide local search facilities. EWS has gained widespread acceptance due to its ease of installation and the powerful search facilities, and is used on many large corporate sites. The security hole would allow a knowledgeable user to type a search query that included commands that would run on the server -- effectively giving the world at large access to that server.

The Excite announcement was e-mailed directly to registered EWS users early this morning, detailing the general nature of the flaw, along with details of how to obtain a fix from the Excite Web site. However, there is some consternation in the Web community over how long it has taken Excite to notify people of the problem. EWS 1.1 has been available since late 1996, and anyone inspecting the code supplied as part of the system could potentially have discovered the flaw.

Full details of the security flaw, how to exploit it, and some suggestions about how to fix it were posted on the well known hacking Web site rootshell.com on New Year's Day. Hackers were therefore potentially in possesion of a "golden key" to Web servers for two weeks before Excite notified users of the problem. The Web community has been astonished not by the fact that a security hole exists, but by the obvious nature of the glitch.

It isn't known if any sites have fallen prey to this but the potential exists that any site running EWS 1.1 may have been hacked "invisibly", with the hacker gaining the access to the system password file via the Excite flaw. They could then use information gained to remove traces of the attack, whilst retaining future access to the server.

As knowledge of the problem becomes more widespread it will be a race against time for sites to implement the fix and close the door to potential hackers. Already concern has been expressed over whether the fix provided by Excite is the best way of tackling the problem, and whether the method used may have security issues of its own.

More News | ZDNet

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
46 out of 108 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:










Related Jobs

VB.Net Developer, North West

Due to the nature of the project work, you are required to be SC Cleared and applications must come from candidates who have already gained this or ...

Data Analyst - Chance to gain formal training on .NET - Berkshire

In your job you will be collating data from all arms of the business, including IT, finance and marketing; uploading it to Access databases and also ...

Price to Win Architect

Your track record of corporate experience and deep understanding of the players in this space will be second to none, and youll have extensive ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment