[NEWS] Dangerous Information in CentraOne Log Files (Vendor Response)

From: support@securiteam.com
Date: 12/27/01


From: support@securiteam.com
To: list@securiteam.com
Date: Thu, 27 Dec 2001 17:18:42 +0100 (CET)

The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

When was the last time you checked your server's security?
How about a monthly report?
http://www.AutomatedScanning.com - Know that you're safe.
- - - - - - - - -

  Dangerous Information in CentraOne Log Files (Vendor Response)
------------------------------------------------------------------------

SUMMARY

This security bug applies to CentraOne v5.2 customers using Centra Smart
Connect patch CEN5.2-03 (released November 11, 2001) and Centra ASP
customers. For both sets of customers, it only applies to users who
connect to the Centra Server through a proxy server that has Basic
Authentication enabled.

When the client launches, a log file is created on the end user's local
PC. If the user is connecting through a proxy server with Basic
Authentication enabled, the log file contains information about the proxy
server including a base64 encoded username / password string. This
information could be used to launch an impersonation attack by an
individual who has physical access to the log files on the end user's
client PC.

DETAILS

Presentation of the vulnerability:
Below is a list of steps you can take to avoid this problem. Please
contact Centra Customer Support for more details.

NOTE: Only applicable to customers using CentraOne 5.2 with Patch
CEN5.2-03 and Centra ASP services

- Upgrade to CentraOne 5.3 General Availability, which is not susceptible
to this problem and is available from Centra today.

- Install the patch designed to address this, which will be available for
download from the Centra customer support web site on or before Friday,
January 4.

- Centra will be adding a patch to the Centra eMeeting ASP service to
address this bug.

ADDITIONAL INFORMATION

The information has been provided by <mailto:JClark@CENTRA.COM> JClark.

========================================

This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.



Relevant Pages

  • Dangerous information in CentraOne log files - VENDOR RESPONSE
    ... As a subscriber itself to the NTBugtraq listserv, Centra Software first ... customers with its response to this vulnerability. ... This security bug applies to CentraOne v5.2 customers using Centra Smart ...
    (NT-Bugtraq)
  • Re: [fw-wiz] Security dumming down - the kings clothes
    ... these networks we have: "it's a trifle chaotic out there". ... responsible for the security portion of this overall process our ... me that our greatest weakness as an industry is not that our customers are ... >>marketing or rhetoric PhD. ...
    (Firewall-Wizards)
  • Re: How do you monetize your skills?
    ... organizations that were dedicate on only the Information Security ... In sales you'll learn that customers that "want" your product/service ... market customer to reach in all of marketing/advertising. ...
    (Pen-Test)
  • Re: Data Center Theft
    ... went wrong, change security and procedures. ... NOT lie to your customers, and put them in the positions that CI Host ... So how is it possible that the facility has been robbed ...
    (bit.listserv.ibm-main)
  • Re: Security and Contingency Planning
    ... Subject: Security and Contingency Planning ... > Hypothetical Situation: ... scenarios should a healthcare provider actually loose data to data theft, ... angles (current customers, former customers, medical staff, union ...
    (Security-Basics)