NT BackOffice Reboot.ini Clear-Text Passwords Vulnerability
BID:228
Info
NT BackOffice Reboot.ini Clear-Text Passwords Vulnerability
| Bugtraq ID: | 228 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Unknown |
| Local: | Yes |
| Published: | Feb 09 1999 12:00AM |
| Updated: | Feb 09 1999 12:00AM |
| Credit: | This vulnerability was discovered by Angelo Maggio and was subsequently posted to NTBugtraq by Russ Cooper. |
| Vulnerable: |
Hancom Hancom Office 2007 0 |
| Not Vulnerable: | |
Discussion
NT BackOffice Reboot.ini Clear-Text Passwords Vulnerability
During installation of BackOffice 4.0, a file called reboot.ini is created and stored in the \Program Files\Microsoft BackOffice directory. This file contains clear-text usernames and passwords for several services that may be created during installation. These services include: SQL Executive Logon, Exchange Services, and MTS Remote Administration (and potentially others). The File ACLs for this file are set to Everyone:Full Control.
During installation of BackOffice 4.0, a file called reboot.ini is created and stored in the \Program Files\Microsoft BackOffice directory. This file contains clear-text usernames and passwords for several services that may be created during installation. These services include: SQL Executive Logon, Exchange Services, and MTS Remote Administration (and potentially others). The File ACLs for this file are set to Everyone:Full Control.
Solution / Fix
NT BackOffice Reboot.ini Clear-Text Passwords Vulnerability
Solution:
Microsoft recommends deleting the \Program Files\Microsoft BackOffice\Reboot.ini file after each installation of BackOffice 4.0.
Solution:
Microsoft recommends deleting the \Program Files\Microsoft BackOffice\Reboot.ini file after each installation of BackOffice 4.0.
References
NT BackOffice Reboot.ini Clear-Text Passwords Vulnerability
References:
References: