|
Legato NetWorker Reverse DNS Authentication Vulnerability
Legato NetWorker is a server package designed to help share data, media and backup processes across a heterogeneous network. As part of the process of authenticating a client, the NetWorker server attempts to verify that their given host matches their given IP address by performing a reverse DNS lookup on the host name. If it is unable to complete this lookup, it continues with the authentication process, trusting the provided information. A remote attacker able to deny reverse DNS lookup to the vulnerable server will be able to authenticate as an arbitrary host, bypassing this check. |
|
|
Privacy Statement |