博客
关于我
强烈建议你试试无所不能的chatGPT,快点击我
JBoss AS Administrative Console Password Disclosure
阅读量:2435 次
发布时间:2019-05-10

本文共 1320 字,大约阅读时间需要 4 分钟。

Product: Embedded Jopr - JBoss AS Administration Console Vendor: Red Hat Middleware, LLC Version: < 1.2 Tested Version: 1.2 Vendor Notified Date: May 29, 2013 Release Date: June 03, 2013 Risk: Moderate Authentication: Required Remote: Yes Description: Passwords submitted to the application are returned in clear form in  later responses from the application. Although the password field is  masked, it is visible via the page source regardless of SSL. This behavior increases the risk that passwords will be captured by an  attacker. Specifically, this can be leveraged to pivot and gain access to  configured databases by viewing the page source or using browser tools  such as "inspect element" in chrome and firefox. Successful exploitation of this vulnerability results in taking  complete control of database servers. Exploit steps for proof-of-concept: 1. Navigate to: JBossAS Servers> JBoss AS> Resources> Datasources 2. Select Datasource 3. View page source 4. Find input type="password" 5. "value=" will contain the database password. 6. Dump database. Vendor Notified: Yes Vendor Response: Does not consider this to be an exploitable security  flaw due to type authenticated. Reference: CVE-2013-3734 http://www.halock.com/blog/cve-2013-3734-jboss-administration-console-password-returned-response/ amroot.com

转载地址:http://ckemb.baihongyu.com/

你可能感兴趣的文章
更改Windows XP 的日期和时间(转)
查看>>
windows2000中的“秘密武器”(三)(转)
查看>>
Linux程序应用开发环境和工具经验谈(转)
查看>>
Linux办公一条龙之电子表格Calc(转)
查看>>
在NETBSD上配置ADSL+IPF+IPNAT(转)
查看>>
Windows 98 使用维护向导(转)
查看>>
用win2000收发传真(转)
查看>>
Linux办公一条龙之初识OpenOffice(转)
查看>>
Linux上安装GCC编译器过程(转)
查看>>
使用Windows XP 的任务计划(转)
查看>>
FreeBSD软盘操作(转)
查看>>
Linux分区工具的使用方法(转)
查看>>
深入理解硬盘的Linux分区(转)
查看>>
循序渐进教你LINUX之软件配置方法(转)
查看>>
解读Linux文件权限的设置方法(转)
查看>>
Ext2 文件系统的硬盘布局(转)
查看>>
Linux不完全手册(二)(转)
查看>>
Linux 7.x TCP Wrapper and xinetd(转)
查看>>
建NetBSD及OpenBSD本地源码库(转)
查看>>
学习NetBSD-基本设置(转)
查看>>