SafeBoot User Enumeration Weakness
BID:7152
Info
SafeBoot User Enumeration Weakness
| Bugtraq ID: | 7152 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 20 2003 12:00AM |
| Updated: | Mar 20 2003 12:00AM |
| Credit: | Discovery of this issue is credited to Chris Crute. |
| Vulnerable: |
Control Break International SafeBoot 4.1 SP2 Control Break International SafeBoot 4.1 SP1 Control Break International SafeBoot 4.1 Control Break International SafeBoot 4.0 SP2a Control Break International SafeBoot 4.0 SP2 Control Break International SafeBoot 4.0 SP1 Control Break International SafeBoot 4.0 Control Break International SafeBoot 3.5 |
| Not Vulnerable: | |
Discussion
SafeBoot User Enumeration Weakness
When an authentication attempt fails, SafeBoot will respond with information as to whether it was the username or password that was incorrect. This will enable an attacker to guess valid usernames, which will aid in brute-force attacks in an attempt to compromise SafeBoot accounts.
When an authentication attempt fails, SafeBoot will respond with information as to whether it was the username or password that was incorrect. This will enable an attacker to guess valid usernames, which will aid in brute-force attacks in an attempt to compromise SafeBoot accounts.
Exploit / POC
SafeBoot User Enumeration Weakness
There is no exploit required.
There is no exploit required.
References
SafeBoot User Enumeration Weakness
References:
References:
- SafeBoot Homepage (Control Break International)
- Safeboot PC Security User Emuneration Vulnerability ("Advisories"
)