Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

Trend Micro Control Manager - Enterprise Edition 3.0 Web application Replay attack
From: "CIRT Advisory" <advisory () cirt dk>
Date: Thu, 13 Jan 2005 19:45:53 +0100

The web application are vulnerable to a replay attack, meaning that the
username and password are encrypted but there are not used any form of
timestamp to make this mechanism more advanced and secure.

If it is possible to sniff the traffic when a user login to the
administrative interface, it is possible to replay this sequence and get a
valid login session, with the rights of the user.

Vendors response to this was, it is a feature not a vulnerability and all
the others also have this problem.

Read the full advisory at http://www.cirt.dk/advisories/cirt-28-advisory.pdf

----------------------------------------------------------------------
Danish Incident Response Team
http://www.cirt.dk
----------------------------------------------------------------------





  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]