HP Secure Web Console

From: Jon Mitchell (jrmat_private)
Date: Wed Dec 01 1999 - 07:05:40 PST

  • Next message: bugtraqat_private: "Re: Default IE 5.0 security settings allow frame spoofing"

    The Secure Web Console is a device that looks (and acts) like a JetDirect
    printserver.  It has one ethernet port and one serial port.  The idea
    behind it is that you can connect your console cable from your HP9000
    machine to this device and put it on the network.  This way you can
    connect to your HP9000's via a web browser so remote access to the console
    is easy.  Since this is actual console access you could potentially do
    upgrades or reboots into single user mode safely from this device without
    being onsite.
    
    The problem with this device is the word Secure in the name.  This implies
    that this device is providing secure access from the network.  The
    information on this devices web site http://www.hp.com/go/webconsole
    states that it currently uses MD5 user digest as the encryption scheme and
    that future firmware will support SSL.  We have the latest firmware
    installed at this time of A1.6 (A.01.06.001)
    
    Upon first connecting we noticed that it would not support an SSL
    connection as the documentation states.  Because even the first page you
    access on this device is a Java applet, we assumed the best, that
    encryption was somehow provided through that.  However we discovered that
    it does not appear to be any sort of MD5 encryption scheme (although I'm
    not an encryption expert), but in actuality what we've deemed Secret
    Decoder Ring encryption.  The letters are one to one with another letter,
    and even worse, in order as well.
    
    Here's an example of two sets of letters:
    
    You type:  abcd
    Transmits: VUTS
    
    You type:  ABCD
    Transmits: vuts
    
    Thanks to Joe Munson for helping debug this and coming up with the Secret
    Decoder Ring reference (which reminded me of the Little Orphan Annie Ring,
    that only says to drink more Ovaltine, in the Christmas Story).
    
    --
    Jon Mitchell
    Systems Engineer, Subject Wills and Company
    jrmat_private
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 15:15:14 PDT