|
Sun Solaris Telnet Remote Authentication Bypass Vulnerability
Attackers may exploit this issue with a telnet client. The following command demonstrates this issue: telnet -l-f<user> <hostname> Or, attackers may execute the following command to bypass the console-only superuser authentication: telnet -l-d/dev/console <hostname> Note that in this case, just the requirement for console-only superuser logins will be bypassed, not the remote authentication. Reports indicate that this issue is being exploited in the wild by a malicious worm. Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild. |
|
|
Privacy Statement |