Arkeia Network Backup Client Remote Access

From: H D Moore (sflist_at_digitaloffense.net)
Date: 02/20/05

  • Next message: H D Moore: "Re: Knox Arkeia remote root/system exploit"
    To: bugtraq@securityfocus.com
    Date: Sun, 20 Feb 2005 14:41:36 -0600
    
    

    Anyone able to connect to TCP port 617 can gain read/write access to the
    filesystem of any host running the Arkeia agent software. This appears to
    be an intentional design decision on the part of the Arkeia developers. A
    long-winded description of this issue, complete with screen shots,
    demonstration code, and packet captures can found online at:

     - http://metasploit.com/research/arkeia_agent/

    -HD


  • Next message: H D Moore: "Re: Knox Arkeia remote root/system exploit"