TOTVS ERP Microsiga Protheus Username Enumeration Weakness
BID:46739
Info
TOTVS ERP Microsiga Protheus Username Enumeration Weakness
| Bugtraq ID: | 46739 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 04 2011 12:00AM |
| Updated: | Mar 04 2011 12:00AM |
| Credit: | Flavio do Carmo Junior aka waKKu from DcLabs Security Research Group |
| Vulnerable: |
TOTVS ERP Microsiga Protheus 8 TOTVS ERP Microsiga Protheus 10 |
| Not Vulnerable: | |
Discussion
TOTVS ERP Microsiga Protheus Username Enumeration Weakness
TOTVS ERP Microsiga Protheus is prone to a username-enumeration weakness because it responds differently to login attempts depending on whether or not the username exists.
Attackers can exploit this weakness to discern valid usernames, which may aid them in brute-force password cracking or other attacks.
TOTVS ERP Microsiga Protheus is prone to a username-enumeration weakness because it responds differently to login attempts depending on whether or not the username exists.
Attackers can exploit this weakness to discern valid usernames, which may aid them in brute-force password cracking or other attacks.
Exploit / POC
TOTVS ERP Microsiga Protheus Username Enumeration Weakness
Attackers can use readily available tools to exploit this issue.
Attackers can use readily available tools to exploit this issue.
Solution / Fix
TOTVS ERP Microsiga Protheus Username Enumeration Weakness
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
TOTVS ERP Microsiga Protheus Username Enumeration Weakness
References:
References:
- Vendor Homepage (TOTVS)
- TOTVS ERP Microsiga Protheus - Users Enumeration (Flavio do Carmo Junior aka waKKu
)