Netopia Timbuktu Cleartext Username/Password Vulnerability
BID:935
Info
Netopia Timbuktu Cleartext Username/Password Vulnerability
| Bugtraq ID: | 935 |
| Class: | Design Error |
| CVE: |
CVE-2000-0086 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 18 2000 12:00AM |
| Updated: | Jul 11 2009 01:56AM |
| Credit: | First posted to Bugtraq by David Masten <[email protected]> on January 16, 2000. |
| Vulnerable: |
Netopia Timbuktu Pro 3.0 Netopia Timbuktu Pro 2.0 |
| Not Vulnerable: |
Netopia Timbuktu Pro Enterprise 2.1 Netopia Timbuktu Pro 2000 |
Discussion
Netopia Timbuktu Cleartext Username/Password Vulnerability
Netopia's Timbuktu Pro is a remote administration software package which runs on Microsoft Windows NT (among other platforms). When a user of a Windows NT host logs into their machine remotely via Timbuktu Pro, the username and password of the user are sent to the host for authentication in cleartext (unencrypted). This allows for anyone who is sniffing network traffic to retrieve the username and password pair, exactly as were typed in by the user, and access the host being logged into as the user logging in (and possibly compromise the entire machine).
Netopia's Timbuktu Pro is a remote administration software package which runs on Microsoft Windows NT (among other platforms). When a user of a Windows NT host logs into their machine remotely via Timbuktu Pro, the username and password of the user are sent to the host for authentication in cleartext (unencrypted). This allows for anyone who is sniffing network traffic to retrieve the username and password pair, exactly as were typed in by the user, and access the host being logged into as the user logging in (and possibly compromise the entire machine).
Exploit / POC
Netopia Timbuktu Cleartext Username/Password Vulnerability
To exploit this, wait for someone on your shared LAN to access a target host with Timbuktu. Sniff the traffic going from user to target host, tcp destination port 1417. The packets containing the characters typed will have (in the data segment) an initial hex sequence of "05 00 3E" each (followed by the uppercased character).
To exploit this, wait for someone on your shared LAN to access a target host with Timbuktu. Sniff the traffic going from user to target host, tcp destination port 1417. The packets containing the characters typed will have (in the data segment) an initial hex sequence of "05 00 3E" each (followed by the uppercased character).
Solution / Fix
Netopia Timbuktu Cleartext Username/Password Vulnerability
Solution:
This issue has been resolved in Netopia Timbuktu Pro Enterprise 2.1 and Timbuktu Pro 2000.
Solution:
This issue has been resolved in Netopia Timbuktu Pro Enterprise 2.1 and Timbuktu Pro 2000.
References
Netopia Timbuktu Cleartext Username/Password Vulnerability
References:
References:
- Netopia TB2 Homepage (Netopia)