Intego FileGuard Weak Password Encryption Vulnerability
BID:3213
Info
Intego FileGuard Weak Password Encryption Vulnerability
| Bugtraq ID: | 3213 |
| Class: | Design Error |
| CVE: |
CVE-2001-1165 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 20 2001 12:00AM |
| Updated: | Jul 11 2009 07:56AM |
| Credit: | This vulnerability was discovered by mSec and submitted to BugTraq on August 20th, 2001 by MacSec <[email protected]>. |
| Vulnerable: |
Intego FileGuard 4.0 Intego DiskGuard 2.0 |
| Not Vulnerable: | |
Discussion
Intego FileGuard Weak Password Encryption Vulnerability
Intego FileGuard is a commercial access control utility for Mac OS versions 7-9.1. It's functionality includes the ability to enforce privileges, log activities, manage user accounts, restrict access by time, etc.
Intego FileGuard provides system level access restrictions to versions of Mac OS that otherwise would not have such access controls. However, a vulnerability exists which allows a local user to circumvent those controls and elevate privileges. A weak algorithm is used to encrypt the stored passwords.
mSec has released a tool called Disengage which will attempt to decrypt passwords, provided circumstances exist which allow Disengage to work. Passwords for Intego DiskGuard may also be decrypted in this manner.
Intego FileGuard is a commercial access control utility for Mac OS versions 7-9.1. It's functionality includes the ability to enforce privileges, log activities, manage user accounts, restrict access by time, etc.
Intego FileGuard provides system level access restrictions to versions of Mac OS that otherwise would not have such access controls. However, a vulnerability exists which allows a local user to circumvent those controls and elevate privileges. A weak algorithm is used to encrypt the stored passwords.
mSec has released a tool called Disengage which will attempt to decrypt passwords, provided circumstances exist which allow Disengage to work. Passwords for Intego DiskGuard may also be decrypted in this manner.
Solution / Fix
Intego FileGuard Weak Password Encryption Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Intego FileGuard Weak Password Encryption Vulnerability
References:
References:
- FileGuard Product Page (Intego)
- FileGuard Security Advisory - Disengage 1.0 (SecureMac)