Arkeia Network Backup Client Remote Access
From: H D Moore (sflist_at_digitaloffense.net)
Date: 02/20/05
- Previous message: Martin Schulze: "[SECURITY] [DSA 674-3] New mailman packages really fix several vulnerabilities"
- Next in thread: Vincent Archer: "Re: Arkeia Network Backup Client Remote Access"
- Reply: Vincent Archer: "Re: Arkeia Network Backup Client Remote Access"
- Reply: H D Moore: "Re: Arkeia Network Backup Client Remote Access"
- Maybe reply: Arnaud Spicht: "Re: Arkeia Network Backup Client Remote Access"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: bugtraq@securityfocus.com Date: Sun, 20 Feb 2005 14:41:36 -0600
Anyone able to connect to TCP port 617 can gain read/write access to the
filesystem of any host running the Arkeia agent software. This appears to
be an intentional design decision on the part of the Arkeia developers. A
long-winded description of this issue, complete with screen shots,
demonstration code, and packet captures can found online at:
- http://metasploit.com/research/arkeia_agent/
-HD
- Previous message: Martin Schulze: "[SECURITY] [DSA 674-3] New mailman packages really fix several vulnerabilities"
- Next in thread: Vincent Archer: "Re: Arkeia Network Backup Client Remote Access"
- Reply: Vincent Archer: "Re: Arkeia Network Backup Client Remote Access"
- Reply: H D Moore: "Re: Arkeia Network Backup Client Remote Access"
- Maybe reply: Arnaud Spicht: "Re: Arkeia Network Backup Client Remote Access"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]