Ignite Realtime Spark Password Encryption Weakness
BID:54736
Info
Ignite Realtime Spark Password Encryption Weakness
| Bugtraq ID: | 54736 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 27 2012 12:00AM |
| Updated: | Jul 27 2012 12:00AM |
| Credit: | Adam Caudill |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Ignite Realtime Spark Password Encryption Weakness
Ignite Realtime Spark is prone to a weak password encryption weakness.
Successful exploits may allow an attacker to decrypt the stored passwords; this may aid in further attacks.
Ignite Realtime Spark 2.6.3 is vulnerable; other versions may also be affected.
Ignite Realtime Spark is prone to a weak password encryption weakness.
Successful exploits may allow an attacker to decrypt the stored passwords; this may aid in further attacks.
Ignite Realtime Spark 2.6.3 is vulnerable; other versions may also be affected.
Exploit / POC
Ignite Realtime Spark Password Encryption Weakness
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
References
Ignite Realtime Spark Password Encryption Weakness
References:
References:
- Ignite Realtime Spark Homepage (Ignite Realtime)
- Spark IM Client Local Password Decryption (Adam Caudill)