what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

safer.98-09-07.exp.1.1

safer.98-09-07.exp.1.1
Posted Sep 23, 1999

safer.98-09-07.exp.1.1

SHA-256 | ea52adfd5a83421bdcc558a06228f2031c197b65c60c5868faa023dc07fdb1a0

safer.98-09-07.exp.1.1

Change Mirror Download

From security@SIAMRELAY.COM Sun Sep 13 08:13:17 1998
From: Security Research Team <security@SIAMRELAY.COM>
X-Sender: vanja@siamrelay.com (Unverified)
To: BUGTRAQ@netspace.org
Date: Thu, 10 Sep 1998 04:59:05 -0400
Subject: SSH 1.2.25/HP-UX 10.20 Vulnerability

__________________________________________________________

S.A.F.E.R. Security Bulletin 980907.EXP.1.1
__________________________________________________________


TITLE : Vulnerability with HP-UX 10.20 and SSH 1.2.25
DATE : September 7, 1998
NATURE : Local compromise (remote under some circumstances)
PLATFORMS : HP-UX 10.20 (possibly other versions of HP-UX)

DETAILS:

A vulnerability exists in HP-UX systems (tested on 10.20 that was converted
to "trusted system") using SSH 1.2.25.

When administrator creates a new user using SAM, no password is assigned,
but a random number is generated which the user needs to input upon first
login.

However, if user connects via SSH using newly created username, no password
authentication is performed and user automatically drops into shell.

This can be especially dangerous on systems where users are added on a
daily basis (universities for example) and other users aware of this bug
could gain access to newly created accounts (remote users could gain
information about new users using finger command, for example).

FIXES:

SSH 1.2.26 is available for over a month now (this problem has been fixed).
Also, version 2.0 of SSH is released (completely rewritten).

They are available for download at: ftp://ftp.cs.hut.fi/pub/ssh/


__________________________________________________________

S.A.F.E.R. - Security Alert For Entreprise Resources
Copyright (c) 1998 Siam Relay Ltd.
http://siamrelay.com/safer --- security@siamrelay.com
__________________________________________________________
Login or Register to add favorites

File Archive:

June 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jun 1st
    0 Files
  • 2
    Jun 2nd
    0 Files
  • 3
    Jun 3rd
    18 Files
  • 4
    Jun 4th
    21 Files
  • 5
    Jun 5th
    0 Files
  • 6
    Jun 6th
    0 Files
  • 7
    Jun 7th
    0 Files
  • 8
    Jun 8th
    0 Files
  • 9
    Jun 9th
    0 Files
  • 10
    Jun 10th
    0 Files
  • 11
    Jun 11th
    0 Files
  • 12
    Jun 12th
    0 Files
  • 13
    Jun 13th
    0 Files
  • 14
    Jun 14th
    0 Files
  • 15
    Jun 15th
    0 Files
  • 16
    Jun 16th
    0 Files
  • 17
    Jun 17th
    0 Files
  • 18
    Jun 18th
    0 Files
  • 19
    Jun 19th
    0 Files
  • 20
    Jun 20th
    0 Files
  • 21
    Jun 21st
    0 Files
  • 22
    Jun 22nd
    0 Files
  • 23
    Jun 23rd
    0 Files
  • 24
    Jun 24th
    0 Files
  • 25
    Jun 25th
    0 Files
  • 26
    Jun 26th
    0 Files
  • 27
    Jun 27th
    0 Files
  • 28
    Jun 28th
    0 Files
  • 29
    Jun 29th
    0 Files
  • 30
    Jun 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close