|
Full Disclosure
mailing list archives
Re: Argentinean Arnet isp webmail
From: "Ing. Juan Perez" <etropos () gmail com>
Date: Fri, 6 Nov 2009 13:38:32 -0300
Confirmed, thanks
and POP3 too:
c:\>telnet pop3.arnet.com.ar 110
+OK
user P0*****4241 () arnet com ar
+OK please, send your password
pass P0*****4241 >>>>>>>>>>>>>> real password
+OK Welcome to your mailbox !!!
quit
+OK Have a nice day!
Se ha perdido la conexión con el host.
+OK
user P0*****4241 () arnet com ar
+OK please, send your password
pass P0*****4 >>>>>>>>>>>>>>> only first 8
+OK Welcome to your mailbox !!!
quit
+OK Have a nice day!
----- Original Message -----
From: <reallyanonymous () hush com>
To: <full-disclosure () lists grok org uk>
Sent: Wednesday, November 04, 2009 8:00 PM
Subject: [Full-disclosure] Argentinean Arnet isp webmail
Moderate vulnerability in argentinean ARNET isp webmail.
well, there is some kind of weakened authentication on the webmail
of Arnet
(webmail.arnet.com.ar) to access any account all you need is to
guess the first 8 characters of the password, even if the password
is 9,10,11,12,14 or more characters long. This password is the same
than ADSL access acount.
for example:
For this account
johndoe () arnet com ar
password:a1a2a3a4a5a6a7a8a9a0
you only need (first 8 character)
johndoe () arnet com ar
password:a1a2a3a4
ADSL account in this case is
Name: johndoe () arnet
Password:a1a2a3a4a5a6a7a8a9a0
there are no anti bruteforce mecanism so you can guess almost any
account within a couple of hours.
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
__________ Información de ESET NOD32 Antivirus, versión de la base de
firmas de virus 4579 (20091106) __________
ESET NOD32 Antivirus ha comprobado este mensaje.
http://www.eset.com
__________ Información de ESET NOD32 Antivirus, versión de la base de firmas de virus 4579 (20091106) __________
ESET NOD32 Antivirus ha comprobado este mensaje.
http://www.eset.com
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
By Date
By Thread
Current thread:
|