Home page logo

fulldisclosure logo Full Disclosure mailing list archives

Argentinean Arnet isp webmail
From: reallyanonymous () hush com
Date: Wed, 04 Nov 2009 20:00:20 -0300

Moderate vulnerability in argentinean ARNET isp webmail.

well, there is some kind of weakened authentication on the webmail 
of Arnet
(webmail.arnet.com.ar) to access any account all you need is to 
guess the first 8 characters of the password, even if the password 
is 9,10,11,12,14 or more characters long. This password is the same 
than ADSL access acount.

for example:

For this account
johndoe () arnet com ar

you only need (first 8 character)

johndoe () arnet com ar

ADSL account in this case is

Name: johndoe () arnet

there are no anti bruteforce mecanism so you can guess almost any 
account within a couple of hours.

Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]