SyGate Non-Authenticated Remote Administration Vulnerability
BID:952
Info
SyGate Non-Authenticated Remote Administration Vulnerability
| Bugtraq ID: | 952 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jan 27 2000 12:00AM |
| Updated: | Jan 27 2000 12:00AM |
| Credit: | Discovered and posted to Bugtraq on Jan 27, 2000 by Robert Hillery <[email protected]>. |
| Vulnerable: |
Sybergen SyGate 3.11 Sybergen SyGate 2.0 |
| Not Vulnerable: | |
Discussion
SyGate Non-Authenticated Remote Administration Vulnerability
SyGate includes a non-documented feature called the Remote Administration Engine (RAE). This feature opens port 7323, and provides a user interface to any incoming telnet session. This interface requires no authentication of any kind, and includes the ability to stop the SyGate service, display various statistics on the SyGate process, and display all TCP or UDP connections, allowing an attacker to generate a map of the internal network.
SyGate includes a non-documented feature called the Remote Administration Engine (RAE). This feature opens port 7323, and provides a user interface to any incoming telnet session. This interface requires no authentication of any kind, and includes the ability to stop the SyGate service, display various statistics on the SyGate process, and display all TCP or UDP connections, allowing an attacker to generate a map of the internal network.
Exploit / POC
SyGate Non-Authenticated Remote Administration Vulnerability
telnet target:7323
telnet target:7323
Solution / Fix
SyGate Non-Authenticated Remote Administration Vulnerability
Solution:
Sybergen has released new builds which correct this issue, available at:
SyGate 3.11 Build 563
http://www.sygate.com/SG563.exe
Upgrading SyGate may require that you upgrade the following two products if you are also running them:
Sybergen Access Server Build 558
http://www.sygate.com/SA558.exe
Sybergen Secure Desktop Build 182
http://www.sygate.com/SD182.exe
Solution:
Sybergen has released new builds which correct this issue, available at:
SyGate 3.11 Build 563
http://www.sygate.com/SG563.exe
Upgrading SyGate may require that you upgrade the following two products if you are also running them:
Sybergen Access Server Build 558
http://www.sygate.com/SA558.exe
Sybergen Secure Desktop Build 182
http://www.sygate.com/SD182.exe
References
SyGate Non-Authenticated Remote Administration Vulnerability
References:
References: