WebTrends Multiple Products Stored Password Vulnerability
BID:513
Info
WebTrends Multiple Products Stored Password Vulnerability
| Bugtraq ID: | 513 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 29 1999 12:00AM |
| Updated: | Jun 29 1999 12:00AM |
| Credit: | ISS Security Advisory released June 29, 1999 and posted to ISS X-Force mailing list. Posted to bugtraq July 4, 1999 by Aleph One <[email protected]>. |
| Vulnerable: |
WebTrends WebTrends Security Analyzer 2.0 WebTrends WebTrends Professional Suite 3.1 WebTrends WebTrends Log Analyzer 4.51 WebTrends WebTrends for Firewalls 1.2 WebTrends WebTrends Enterprise Suite 3.5 |
| Not Vulnerable: | |
Discussion
WebTrends Multiple Products Stored Password Vulnerability
Several WebTrends products can be configured to run as a service at startup and use the MAPI features of Windows NT to email reports. The account and MAPI profiles used, along with the passwords for each, are stored in the WebTrend.ini file in the program's installation folder. This file has Everyone: Full Access permissions by default. The stored passwords are encrypted with a weak algorithm.
Several WebTrends products can be configured to run as a service at startup and use the MAPI features of Windows NT to email reports. The account and MAPI profiles used, along with the passwords for each, are stored in the WebTrend.ini file in the program's installation folder. This file has Everyone: Full Access permissions by default. The stored passwords are encrypted with a weak algorithm.
Exploit / POC
WebTrends Multiple Products Stored Password Vulnerability
see discussion
see discussion
Solution / Fix
WebTrends Multiple Products Stored Password Vulnerability
Solution:
All affected products have newer versions that include 128-bit encryption. Also, modify the permissions for the WebTrend.ini file.
Solution:
All affected products have newer versions that include 128-bit encryption. Also, modify the permissions for the WebTrend.ini file.
References
WebTrends Multiple Products Stored Password Vulnerability
References:
References: