|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
[Full-Disclosure] Arkeia Network Backup Client Remote Access
From: H D Moore (fdlist
digitaloffense.net)
Date: Sun Feb 20 2005 - 14:42:20 CST
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Anyone able to connect to TCP port 617 can gain read/write access to the
filesystem of any host running the Arkeia agent software. This appears to
be an intentional design decision on the part of the Arkeia developers. A
long-winded description of this issue, complete with screen shots,
demonstration code, and packet captures can found online at:
- http://metasploit.com/research/arkeia_agent/
-HD
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]