Centra CentraOne Encoded Credentials Log File Vulnerability
BID:3704
Info
Centra CentraOne Encoded Credentials Log File Vulnerability
| Bugtraq ID: | 3704 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 17 2001 12:00AM |
| Updated: | Dec 17 2001 12:00AM |
| Credit: | Discovery of this vulnerability is credited to [email protected]. |
| Vulnerable: |
Centra Smart Connect CEN5.2-03 Centra CentraOne 5.2 Centra ASP |
| Not Vulnerable: |
Centra CentraOne 5.3 |
Discussion
Centra CentraOne Encoded Credentials Log File Vulnerability
CentraOne is a commercially available education software package. It is maintained and distributed by Centra.
The CenturaOne software stores the user and password credentials in the CentraOne log file, and does not set secure permissions on the log file. In addition to insecure log file permissions, the data is stored using an insecure encoding method.
It should be noted that this only affects systems which connect to the Centra Server through a proxy server which has Basic Authentication enabled.
CentraOne is a commercially available education software package. It is maintained and distributed by Centra.
The CenturaOne software stores the user and password credentials in the CentraOne log file, and does not set secure permissions on the log file. In addition to insecure log file permissions, the data is stored using an insecure encoding method.
It should be noted that this only affects systems which connect to the Centra Server through a proxy server which has Basic Authentication enabled.
Exploit / POC
Centra CentraOne Encoded Credentials Log File Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Centra CentraOne Encoded Credentials Log File Vulnerability
Solution:
The vendor has released an upgraded version of CentraOne which addresses this issue. A patch is also available and can be obtained from the referenced vendor website.
Centra CentraOne 5.2
Solution:
The vendor has released an upgraded version of CentraOne which addresses this issue. A patch is also available and can be obtained from the referenced vendor website.
Centra CentraOne 5.2
-
Centra CentraOne 5.3
http://www.centra.com/
References
Centra CentraOne Encoded Credentials Log File Vulnerability
References:
References:
- Centra Product Page (Centra)