PrimeBase SQL Database server cleartext password storage. (fwd)

From: Larry W. Cashdollar (lwc_at_vapid.ath.cx)
Date: 11/22/03

  • Next message: Gregory LEBRAS: "[SCSA-021] Anonymous Mail Forwarding Vulnerabilities in vbPortal"
    Date: Sat, 22 Nov 2003 10:20:20 -0500 (EST)
    To: <bugtraq@securityfocus.com>
    
    

    PrimeBase SQL Database server cleartext password storage.
    Vapid Labs Security Note
    10/20/03

            The PrimeBase SQL Database Server 4.2 stores passwords in clear
    text, and based on the installation users umask settings maybe readable by
    all local users.

    From the readme.txt file:

    "The Admin server will require you to enter your password in a text file
    called 'password.adm' (in the server folder), before you can continue.
    NOTE: This is the password for access to the Admin Server only."

    Depending on your umask settings (default 022 for root) the "Admin Server"
    password maybe readable by local users. Also the password is not stored
    as a hash or encrypted. A malicious user could uses this password to
    access the web based administration server and compromise the system.

    The database also comes with a default "Administrator" account with no
    password, the documentation does recommend the installer set the
    Administrator password during installation.

    Recommendations: Store the password as a hash in a file read-only by the
    Admin Server. Disable the Administrator account until a password has been
    set for it.

    References: http://www.primebase.de

    Larry Cashdollar
    http://vapid.dhs.org


  • Next message: Gregory LEBRAS: "[SCSA-021] Anonymous Mail Forwarding Vulnerabilities in vbPortal"

    Relevant Pages

    • Re: FOR A SKILLED IT EXPERT - WIN2K SERVER - DOMAIN CONTROLLER
      ... After installing a parallel copy of WIN2K SERVER, ... Administrator access in Directory Services Restore Safe Mode. ... > Thanks Roger - OK - just finished a second windows server installation> to ... > Will try this and see if she boots up in the first installation.... ...
      (microsoft.public.win2000.security)
    • RE: installation error at server application installation
      ... This issue may be cause if there are some errors with the administrator ... Under Component Selection, set Server Tools to ... Microsoft CSS Online Newsgroup Support ... installation error at server application installation ...
      (microsoft.public.windows.server.sbs)
    • Re: Help setting up AD without MS exchange...please!
      ... It is not the AD installation that is a problem, ... It will provide you an easier management option from the administrator view, without going to any machine in the future, as you said yourself. ... AD relies on a functioning DNS setup and user accounts created in AD will, even if they have the same name as the now used local accounts, create a new user profile so basically the users will have to start reconfiguring there profile settings, display, shortcuts etc. etc. ... Windows Server 2003 on our "server", mostly a file and print server. ...
      (microsoft.public.windows.server.active_directory)
    • Re: Trouble Launching Apps
      ... overs from the previous installation, in HKLM and the shadow area, ... Administrator account (or deleting the existing user profile of the ... MCSE, CCEA, Microsoft MVP - Terminal Server ... users, regardless if they also installed the app, can access it. ...
      (microsoft.public.windows.terminal_services)
    • Re: ActiveX is installed but runs only for Administrator
      ... My application runs only for the Administrator who installed the ... Some applications create HKEY_CURRENT_USER registry settings the ... installation, and WHILE THE SERVER IS STILL IN INSTALL MODE. ...
      (microsoft.public.windows.terminal_services)