AmTote Homebet World Accessible Log Vulnerability
BID:3370
Info
AmTote Homebet World Accessible Log Vulnerability
| Bugtraq ID: | 3370 |
| Class: | Configuration Error |
| CVE: |
CVE-2001-1170 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 28 2001 12:00AM |
| Updated: | Jul 11 2009 07:56AM |
| Credit: | This vulnerability was discovered by Gary O'leary-Steele <[email protected]>. |
| Vulnerable: |
AmTote Homebet 0 |
| Not Vulnerable: | |
Discussion
AmTote Homebet World Accessible Log Vulnerability
AmTote Homebet is an Internet-based account wagering interface.
Homebet stores all account and corresponding PIN numbers in the homebet.log file stored in the Homebet virtual directory. On a default installation, the homebet.log file is world readable. This could allow an attacker to steal the log file and strip out the account and PIN numbers.
AmTote Homebet is an Internet-based account wagering interface.
Homebet stores all account and corresponding PIN numbers in the homebet.log file stored in the Homebet virtual directory. On a default installation, the homebet.log file is world readable. This could allow an attacker to steal the log file and strip out the account and PIN numbers.
Exploit / POC
AmTote Homebet World Accessible Log Vulnerability
The following script provided by Gary O'leary-Steele <[email protected]> will extract account and PIN numbers from the homebet.log file:
The following script provided by Gary O'leary-Steele <[email protected]> will extract account and PIN numbers from the homebet.log file:
Solution / Fix
AmTote Homebet World Accessible Log Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.