Cryptcat Encrypted Connection Weakness
BID:8431
Info
Cryptcat Encrypted Connection Weakness
| Bugtraq ID: | 8431 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 11 2001 12:00AM |
| Updated: | Dec 11 2001 12:00AM |
| Credit: | Discovery is credited to "Eric Sheesley" <[email protected]>. |
| Vulnerable: |
Cryptcat Cryptcat 1.10 |
| Not Vulnerable: | |
Discussion
Cryptcat Encrypted Connection Weakness
Cryptcat does not encrypt connections when run in server mode, even when instructed to do so via the -e command line switch. This may lead to a user to believe that the connection is encrypted when it is not, creating a false sense of security and exposing potentially sensitive information to eavesdroppers.
Cryptcat does not encrypt connections when run in server mode, even when instructed to do so via the -e command line switch. This may lead to a user to believe that the connection is encrypted when it is not, creating a false sense of security and exposing potentially sensitive information to eavesdroppers.
Exploit / POC
Cryptcat Encrypted Connection Weakness
There is no exploit required.
There is no exploit required.
Solution / Fix
Cryptcat Encrypted Connection Weakness
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.