UltraEdit FTP Client Weak Password Encryption Vulnerability
BID:3234
Info
UltraEdit FTP Client Weak Password Encryption Vulnerability
| Bugtraq ID: | 3234 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 23 2001 12:00AM |
| Updated: | Aug 23 2001 12:00AM |
| Credit: | This vulnerability was submitted to BugTraq on August 23rd, 2001 by "E. van Elk" <[email protected]>. |
| Vulnerable: |
IDM Computer Solutions UltraEdit-32 8.2 |
| Not Vulnerable: | |
Discussion
UltraEdit FTP Client Weak Password Encryption Vulnerability
UltraEdit is a multi-featured commercial text editor with support for HTML, C/C++, VB, Java, Perl, XML, and C#. It also includes a hex editor and a small FTP client.
UltraEdit's FTP client has a feature which will remember FTP passwords for later use. When passwords are remembered they will be stored on the system using an "admittedly" weak encryption algorithm. As a result, it is a fairly trivial task to decrypt the passwords for FTP accounts.
Successful exploitation of this vulnerability will allow a local attacker to gain unauthorized access to the FTP sites used by other local users.
UltraEdit is a multi-featured commercial text editor with support for HTML, C/C++, VB, Java, Perl, XML, and C#. It also includes a hex editor and a small FTP client.
UltraEdit's FTP client has a feature which will remember FTP passwords for later use. When passwords are remembered they will be stored on the system using an "admittedly" weak encryption algorithm. As a result, it is a fairly trivial task to decrypt the passwords for FTP accounts.
Successful exploitation of this vulnerability will allow a local attacker to gain unauthorized access to the FTP sites used by other local users.