Internet Config for MacOS Weak Password Encryption Vulnerability
BID:546
Info
Internet Config for MacOS Weak Password Encryption Vulnerability
| Bugtraq ID: | 546 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 28 1999 12:00AM |
| Updated: | Jul 28 1999 12:00AM |
| Credit: | Vulnerability emailed to SecurityFocus by SecureMac.com . Most of the information in this listing, including the exploit, was from an article at http://www.securemac.com by Dawid adix Adamski <[email protected] >. |
| Vulnerable: |
Quinn "the Eskimo" and Peter N. Lewis Internet Config 2.0 Quinn "the Eskimo" and Peter N. Lewis Internet Config 1.0 |
| Not Vulnerable: | |
Discussion
Internet Config for MacOS Weak Password Encryption Vulnerability
Internet Config is a third-party freeware utility for MacOS. It provides a means of centralizing frequently-required connection information, including passwords, for use by several programs. The passwords are stored in encrypted form in the Internet Preferences file in the Preferences folder. The encryption algorithm used is weak and easily broken.
Internet Config is a third-party freeware utility for MacOS. It provides a means of centralizing frequently-required connection information, including passwords, for use by several programs. The passwords are stored in encrypted form in the Internet Preferences file in the Preferences folder. The encryption algorithm used is weak and easily broken.
References
Internet Config for MacOS Weak Password Encryption Vulnerability
References:
References:
- Internet Config FAQ (Quinn "The Eskimo" and Peter N. Lewis)
- Password weakness in Internet Config in MacOS (SecureMac)