RE: ARCserve 6.61 Share Access Vulnerability

From: Paulo Filipe Mira (paulo.mira@soquimica.pt)
Date: 09/17/01


From: "Paulo Filipe Mira" <paulo.mira@soquimica.pt>
To: <bugtraq-return-2063-paulo.mira=soquimica.pt@securityfocus.com>, <bugtraq@securityfocus.com>
Subject: RE: ARCserve 6.61 Share Access Vulnerability
Date: Mon, 17 Sep 2001 17:02:56 +0100
Message-ID: <004601c13f92$38237ef0$795541c2@soquimica.pt>

Confirmed in Arcserve 2000 Advanced Edition,
v. 7.0, build 1050, SP2.

> -----Original Message-----
> From: ron [mailto:rdr@steelrat.kernelsutra.com]
> Sent: domingo, 16 de Setembro de 2001 5:27
> To: bugtraq@securityfocus.com
> Subject: ARCserve 6.61 Share Access Vulnerability
>
>
> I have found a vulnerability with ARCServe for NT 6.61 SP2a.
> I stumbled upon this while performing a vulnerability analysis.

--- snip ---

> I am not sure if this is in ARCServe 2000 or in releases
> prior, as I have not checked them.
>
> - rdr
>



Relevant Pages

  • AW: ARCserve 6.61 Share Access Vulnerability
    ... Subject: AW: ARCserve 6.61 Share Access Vulnerability ... ARCserve 6.61 Share Access Vulnerability ... the password for the account is in cleartext. ... the backup account and the administrator access to the share. ...
    (Bugtraq)
  • ARCserve 6.61 Share Access Vulnerability
    ... ARCserve 6.61 Share Access Vulnerability ... I have found a vulnerability with ARCServe for NT 6.61 SP2a. ... the account name that runs the backup is in cleartext within this file. ...
    (Bugtraq)
  • Re: ARCserve 6.61 Share Access Vulnerability
    ... ARCserve 6.61 Share Access Vulnerability ... I had informed them on Sept. 7 and they were relatively quick with a patch ... Can the mentioned permissions be used? ...
    (Bugtraq)