what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Oracle Exadata Leaf Switch Weak Logins

Oracle Exadata Leaf Switch Weak Logins
Posted Nov 29, 2012
Authored by Larry W. Cashdollar

Oracle Exadata leaf switches come configured with easily guessable passwords and a shadow file that is world-readable.

tags | exploit
SHA-256 | 4656654c3f194537f44fd57130e17703524ad55c4635083060dae1b01824ac10

Oracle Exadata Leaf Switch Weak Logins

Change Mirror Download
Oracle Exadata leaf switch logins

From Oracle.com "Oracle Exadata is the only database machine that provides extreme performance for both data warehousing and OLTP applications, making it the ideal platform for consolidating on private clouds. It is a complete package of servers, storage, networking, and software that is massively scalable, secure, and redundant. With Oracle Exadata customers can reduce IT costs through consolidation, store up to ten times more data, improve performance of all applications, deliver a faster time-to-market by eliminating systems integration trial and error, and make better business decisions in real time."

http://www.oracle.com/us/products/database/exadata/overview/index.html

The oracle engineered solution contains two leaf switches and in larger installations a spine switch. The installation I worked with didn't have a spine switch, but the two leaf switches were configured with three logins with easily guessable passwords and a shadow file that was world readable.

There are three accounts with easily guessable default passwords on the exadata inifiniband switches:

ilom-admin,ilom-operator and nm2user.
rux0r:~ meep0$ ssh ilom-admin@192.168.0.113 "cat /conf/shadow"

The shadow file is world readable:

[root@exad-1swib2 ~]# ls -l /conf/shadow -rw-r--r-- 1 root root 749 Dec 23 2011 /conf/shadow

Vendor: notified 3/12/2012
Larry W. Cashdollar

Twitter @_larry0
Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    0 Files
  • 8
    Nov 8th
    0 Files
  • 9
    Nov 9th
    0 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    0 Files
  • 12
    Nov 12th
    0 Files
  • 13
    Nov 13th
    0 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close