Ipswitch IMail Server Weak Password Encryption Weakness
BID:10956
Info
Ipswitch IMail Server Weak Password Encryption Weakness
| Bugtraq ID: | 10956 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 20 1999 12:00AM |
| Updated: | Dec 20 1999 12:00AM |
| Credit: | Discovery of this weakness is credited to Matt Conover <shok_at_CANNABIS.DATAFORCE.NET>. |
| Vulnerable: |
Ipswitch IMail 8.1 Ipswitch IMail 8.0.5 Ipswitch IMail 8.0.3 Ipswitch IMail 7.12 Ipswitch IMail 7.1 Ipswitch IMail 7.0.7 Ipswitch IMail 7.0.6 Ipswitch IMail 7.0.5 Ipswitch IMail 7.0.4 Ipswitch IMail 7.0.3 Ipswitch IMail 7.0.2 Ipswitch IMail 7.0.1 Ipswitch IMail 6.4 Ipswitch IMail 6.3 Ipswitch IMail 6.2 Ipswitch IMail 6.1 Ipswitch IMail 6.0.6 Ipswitch IMail 6.0.5 Ipswitch IMail 6.0.4 Ipswitch IMail 6.0.3 Ipswitch IMail 6.0.2 Ipswitch IMail 6.0.1 Ipswitch IMail 6.0 Ipswitch IMail 5.0.8 Ipswitch IMail 5.0.7 Ipswitch IMail 5.0.6 Ipswitch IMail 5.0.5 Ipswitch IMail 5.0 |
| Not Vulnerable: | |
Discussion
Ipswitch IMail Server Weak Password Encryption Weakness
Ipswitch IMail is reported to use a weak encryption algorithm when obfuscating saved passwords. A local attacker who has the ability to read the encrypted passwords may easily derive the plaintext password if the username that is associated with the password is known.
A local attacker may exploit this weakness to disclose user credentials.
Ipswitch IMail is reported to use a weak encryption algorithm when obfuscating saved passwords. A local attacker who has the ability to read the encrypted passwords may easily derive the plaintext password if the username that is associated with the password is known.
A local attacker may exploit this weakness to disclose user credentials.
Exploit / POC
Ipswitch IMail Server Weak Password Encryption Weakness
The following exploit is available:
The following exploit is available:
Solution / Fix
Ipswitch IMail Server Weak Password Encryption Weakness
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Ipswitch IMail Server Weak Password Encryption Weakness
References:
References:
- [w00giving '99 #11] IMail's password encryption scheme (Matt Conover
) - IMail Home Page (Ipswitch)
- IpSwitch IMail Server <= ver 8.1 User Password Decryption (Adik
) - IpSwitch IMail Server <= ver 8.1 User Password Decryption (Adik
) - RE: IpSwitch IMail Server <= ver 8.1 User Password Decryption ("Bill Roemhild"
) - Re: IpSwitch IMail Server <= ver 8.1 User Password Decryption ("David E. Smith"
)