Dynamic DNS Update Client Credentials Obfuscation Vulnerability
BID:41121
Info
Dynamic DNS Update Client Credentials Obfuscation Vulnerability
| Bugtraq ID: | 41121 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 24 2010 12:00AM |
| Updated: | Jun 24 2010 12:00AM |
| Credit: | sinn3r |
| Vulnerable: |
No-IP Dynamic Update Client 2.2.1 No-IP Dynamic Update Client 2.1.9 No-IP Dynamic Update Client 2.1.8 No-IP Dynamic Update Client 2.1.7 No-IP Dynamic Update Client 0 |
| Not Vulnerable: | |
Discussion
Dynamic DNS Update Client Credentials Obfuscation Vulnerability
Dynamic DNS Update Client is prone to a security vulnerability that may allow attackers to decode sensitive information.
Successfully exploiting this issue may allow attackers to gain access to sensitive information. Information obtained may aid in further attacks.
Dynamic DNS Update Client 2.2.1 is vulnerable; other versions may also be affected.
Dynamic DNS Update Client is prone to a security vulnerability that may allow attackers to decode sensitive information.
Successfully exploiting this issue may allow attackers to gain access to sensitive information. Information obtained may aid in further attacks.
Dynamic DNS Update Client 2.2.1 is vulnerable; other versions may also be affected.
Exploit / POC
Dynamic DNS Update Client Credentials Obfuscation Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
Dynamic DNS Update Client Credentials Obfuscation Vulnerability
Solution:
Reports indicate that this issue has been fixed. Pleases see the references for more information.
Solution:
Reports indicate that this issue has been fixed. Pleases see the references for more information.
References
Dynamic DNS Update Client Credentials Obfuscation Vulnerability
References:
References: