L0phtcrack 2.5 - passwords exposed Vulnerability
BID:144
Info
L0phtcrack 2.5 - passwords exposed Vulnerability
| Bugtraq ID: | 144 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Unknown |
| Published: | Jan 06 1999 12:00AM |
| Updated: | Jan 06 1999 12:00AM |
| Credit: | |
| Vulnerable: |
L0pht L0phtCrack 2.5 0 |
| Not Vulnerable: |
L0pht L0phtCrack 2.5.1 |
Discussion
L0phtcrack 2.5 - passwords exposed Vulnerability
L0phtCrack 2.50 stores copies of the password hashes dumped from a Registry or SAM file in the %systemroot%\temp directory. In addition, cracked passwords are stored in the same location upon execution of the auto-save function. Passwords and/or their hashes may exist in files such as 'passwd??' or 'passwed??.lc'.
L0phtCrack 2.50 stores copies of the password hashes dumped from a Registry or SAM file in the %systemroot%\temp directory. In addition, cracked passwords are stored in the same location upon execution of the auto-save function. Passwords and/or their hashes may exist in files such as 'passwd??' or 'passwed??.lc'.
Exploit / POC
L0phtcrack 2.5 - passwords exposed Vulnerability
The %systemroot%\temp directory default ACL permissions may allow unauthorized users to view these password hashes or clear-text passwords.
The %systemroot%\temp directory default ACL permissions may allow unauthorized users to view these password hashes or clear-text passwords.
Solution / Fix
L0phtcrack 2.5 - passwords exposed Vulnerability
Solution:
Upgrade to L0phtCrack version 2.51
Solution:
Upgrade to L0phtCrack version 2.51
References
L0phtcrack 2.5 - passwords exposed Vulnerability
References:
References: