DCForum Predictable Password Generation Vulnerability
BID:4014
Info
DCForum Predictable Password Generation Vulnerability
| Bugtraq ID: | 4014 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 31 2002 12:00AM |
| Updated: | Jan 31 2002 12:00AM |
| Credit: | Published by shimi <[email protected]>. |
| Vulnerable: |
DC Scripts DCForum 2000 1.0 DC Scripts DCForum 6.21 DC Scripts DCForum 6.0 DC Scripts DCForum 5.0 |
| Not Vulnerable: |
DC Scripts DCForum 6.22 DC Scripts DCForum 4.0 DC Scripts DCForum 3.0 DC Scripts DCForum 2.0 DC Scripts DCForum 1.0 |
Discussion
DCForum Predictable Password Generation Vulnerability
DCForum is a web based conferencing system, designed to facilitate online discussion. It is implemented in Perl and has few system dependancies, making it available on most operating systems, including Linux, Windows and most Unix varients.
The new password functionality of DCForum, used to recover lost or forgotten passwords, creates passwords with data taken from the session id. This effectively sets the new password to a known value. This function is available to any remote user, and can be used to compromise arbitrary DCForum accounts, including those with administrative privileges.
This algorithm is also used in the generation of new accounts, if the user is not allowed to select their own initial password. This may allow an attacker to create a valid account without the need for a valid email address.
DCForum is a web based conferencing system, designed to facilitate online discussion. It is implemented in Perl and has few system dependancies, making it available on most operating systems, including Linux, Windows and most Unix varients.
The new password functionality of DCForum, used to recover lost or forgotten passwords, creates passwords with data taken from the session id. This effectively sets the new password to a known value. This function is available to any remote user, and can be used to compromise arbitrary DCForum accounts, including those with administrative privileges.
This algorithm is also used in the generation of new accounts, if the user is not allowed to select their own initial password. This may allow an attacker to create a valid account without the need for a valid email address.
Exploit / POC
DCForum Predictable Password Generation Vulnerability
No exploit code is required to take advantage of this issue.
No exploit code is required to take advantage of this issue.
Solution / Fix
DCForum Predictable Password Generation Vulnerability
Solution:
Version 6.22 has been released, and is no longer vulnerable. Registered users should contact the vendor for an update.
A fix has been made available:
DC Scripts DCForum 6.0
DC Scripts DCForum 6.21
Solution:
Version 6.22 has been released, and is no longer vulnerable. Registered users should contact the vendor for an update.
A fix has been made available:
DC Scripts DCForum 6.0
-
DC Scripts retrieve_password.txt
http://www.dcscripts.com/FAQ/retrieve_password.txt
DC Scripts DCForum 6.21
-
DC Scripts retrieve_password.txt
http://www.dcscripts.com/FAQ/retrieve_password.txt
References
DCForum Predictable Password Generation Vulnerability
References:
References:
- DCScripts DCForum Homepage (DCScripts)
- Jan 31, 2002 - security advisory (DCScripts)
- Severe Security Violation - Latest DCForum (DCScripts)