Notification

Urchin WebAnalytics Software is discontinued and is no longer supported. All Urchin documentation applies only to the Urchin product as it was at the time of discontinuation, and does not apply to any Google Analytics products or services.

Vulnerability Using HTTP TRACE wth Apache 1.3: Limited Urchin 4 Exposure

Overview

Urchin 4 ships with an embedded Apache webserver that provides access to the web-based Urchin administration and reporting functions. The default Apache configuration as shipped with Urchin allows use of the Trace HTTP request. Per the following CERT security advisory:

this behavior could be leveraged by attackers to access sensitive information, such as cookies or authentication data, contained in the HTTP headers of the request.

Impact on Urchin Customers

The suggested remediation as described in the CERT advisory involves the use of the Apache mod_rewrite module. Apache's official position on this issue is that it is a browser problem, and not an issue with the Apache webserver itself, and that the suggested workaround does not eliminate the possibility of utilizing the published attack to obtain sensitive information. After careful examination of the fix and the threat, Urchin Software Corporation's position on this issue is that:

  1. The mod_rewrite module adds an unnecessary complexity to the Apache webserver shipped with Urchin which does not eliminate the security issue described
  2. The vulnerability as it applies to communications between the Urchin interface and a user's browser does not present a threat to system security
Therefore, there are currently no plans to incorporate a workaround into the Apache webserver that ships with Urchin 4. Customers are welcome to implement the mod_rewrite fix on their own, but it is not a modification that we support. Please do so at your own risk. Upgrades to Urchin will automatically overwrite the existing Apache configuration, so any modifications you make to Urchin's Apache configuration will need to be reimplemented after an upgrade.

See Also

Search
Clear search
Close search
Main menu
15827949363001672177
true
Search Help Center
true
true
true
false
false