Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

iSCSI Insecure Configuration File Permissions Information Disclosure Vulnerability

iSCSI leaves administrative credentials stored in a world-readable configuration file.

The configuration file that iSCSI uses is stored in /etc/iscsi.conf. Reportedly, this file is installed, by default, with world readable and possibly world writeable permissions enabled. This may have some potentially serious consequences as the configuration file also stores password information in plain text.







 

Privacy Statement
Copyright 2008, SecurityFocus