Information Disclosure Vulnerability in bitboard2

From: Marc Bromm (theblacksheepat_private)
Date: Wed Jul 09 2003 - 02:22:56 PDT

  • Next message: Cisco Systems Product Security Incident Response Team: "Cisco Security Advisory: Denial-of-Service of TCP-based Services in CatOS"

     ================================================
    <------------------------------------------------>
    <------------#www.bright-shadows.net#------------>
    <------------------------------------------------>
    <--------------#theblacksheep&erik#-------------->
    <------------------------------------------------>
     ================================================
    
    Advisory Information
    --------------------
    Advisory Name      : Information Disclosure Vulnerability in bitboard2
    Author             : Marc Bromm <theblacksheepat_private> Germany
    Discover by        : Marc Bromm <theblacksheepat_private> Germany
    Release Date       : 9. Juli 2003
    Application        : bitboard2 (textfile based board)
    Vendor Homepage    : http://www.bitshifters.bl.am
    Vendor Status      : notified
    Vulnerable Versions: bitboard2  (maybe older)
    Platforms          : OS Independent, PHP
    Severity           : High
    
    ######Overview:
    
    The bitboard2 is a board that need no database to work. So it is useful
    for webmaster that have no access to a sql database.
    
    ######Exploit:
    
    1. Get the admin passwort hash
    
    The crypt hash of the admin password is stored in
    "/admin/data_passwd.dat".
    Everyone has access to it. So only get the hash and crackit with john.
    
    The real problem is that many admins don't use secure passwort ;-)
    
    ######Vendor Response:
    
    They told me that they are going to fix it in the next version.
    
    Greetz to:
    
    Erik, (O_o)oOoOoOo.
    -- 
      
      theblacksheepat_private
    
    -- 
    http://www.fastmail.fm - The professional email service
    



    This archive was generated by hypermail 2b30 : Wed Jul 09 2003 - 13:09:35 PDT