Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email firstname.lastname@example.org
Re: [Full-Disclosure] Arkeia Network Backup Client Remote Access
From: H D Moore (fdlistdigitaloffense.net)
Date: Mon Feb 21 2005 - 21:01:29 CST
Just to clarify, the user manual *does* mention client security and gives
instructions for locking down the Arkeia agent. Unfortunately this is not
enabled by default and only restricts access on a per-host basis.
Appendix B: System Security (not sure how I missed this before)
On Sunday 20 February 2005 14:41, I wrote:
> Anyone able to connect to TCP port 617 can gain read/write access to
> the filesystem of any host running the Arkeia agent software.
Full-Disclosure - We believe in it.