Counterpane Password Safe Insecure Encryption Vulnerability
BID:15455
Info
Counterpane Password Safe Insecure Encryption Vulnerability
| Bugtraq ID: | 15455 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 16 2005 12:00AM |
| Updated: | Nov 16 2005 12:00AM |
| Credit: | ElcomSoft Co.Ltd. discovered this vulnerability. |
| Vulnerable: |
Counterpane Password Safe 2.13 Counterpane Password Safe 1.92 b Counterpane Password Safe 1.7.1 Counterpane Password Safe 2.x |
| Not Vulnerable: | |
Discussion
Counterpane Password Safe Insecure Encryption Vulnerability
Counterpane Password Safe is susceptible to an insecure encryption vulnerability that allows easier brute force decryption attacks.
Password Safe uses a key-stretching algorithm designed to dramatically slow down brute force password guessing attacks. A random value is encrypted with the Blowfish algorithm one thousand times with a value derived from the password used as the encryption key. In order to brute force attack the Password Safe database, an attacker must follow the same one thousand encryption steps on every password guess. This is done to make brute force attacks much more time and resource intensive, lowering the likelihood of a successful attack.
This vulnerability allows attackers with access to the Password Safe database to employ a brute force password guessing attack against the database much more efficiently that the Password Safe design intended. The data contained in the Password Safe database aids malicious users in further attacks.
Counterpane Password Safe is susceptible to an insecure encryption vulnerability that allows easier brute force decryption attacks.
Password Safe uses a key-stretching algorithm designed to dramatically slow down brute force password guessing attacks. A random value is encrypted with the Blowfish algorithm one thousand times with a value derived from the password used as the encryption key. In order to brute force attack the Password Safe database, an attacker must follow the same one thousand encryption steps on every password guess. This is done to make brute force attacks much more time and resource intensive, lowering the likelihood of a successful attack.
This vulnerability allows attackers with access to the Password Safe database to employ a brute force password guessing attack against the database much more efficiently that the Password Safe design intended. The data contained in the Password Safe database aids malicious users in further attacks.
Exploit / POC
Counterpane Password Safe Insecure Encryption Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Counterpane Password Safe Insecure Encryption Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Counterpane Password Safe Insecure Encryption Vulnerability
References:
References: