trixbox Username Enumeration Weakness
BID:48503
Info
trixbox Username Enumeration Weakness
| Bugtraq ID: | 48503 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 29 2011 12:00AM |
| Updated: | Jun 29 2011 12:00AM |
| Credit: | Francesco Tornieri |
| Vulnerable: |
Fonality trixbox 2.8.0.4 |
| Not Vulnerable: | |
Discussion
trixbox Username Enumeration Weakness
trixbox is prone to a username-enumeration weakness because it responds differently to login attempts, depending on whether or not the username exists.
Attackers may exploit this weakness to discern valid usernames, which may aid them in brute-force password cracking or other attacks.
trixbox 2.8.0.4 is vulnerable; other versions may also be affected.
trixbox is prone to a username-enumeration weakness because it responds differently to login attempts, depending on whether or not the username exists.
Attackers may exploit this weakness to discern valid usernames, which may aid them in brute-force password cracking or other attacks.
trixbox 2.8.0.4 is vulnerable; other versions may also be affected.
Exploit / POC
trixbox Username Enumeration Weakness
Attackers can use readily available tools to exploit this issue.
Attackers can use readily available tools to exploit this issue.
Solution / Fix
trixbox Username Enumeration Weakness
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
trixbox Username Enumeration Weakness
References:
References:
- trixbox Homepage (trixbox)
- VOIPPACK 1.4 with added support for Cisco and Trixbox (Enablesecurity)