exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

netforceNIS.txt

netforceNIS.txt
Posted Oct 6, 2005
Authored by bambenek

The NetFORCE 800 version 4.02 M10 will happily send the NIS password map of any domain it is bound to when mailing off diagnostic e-mails.

tags | advisory
SHA-256 | b36910c0efc174c8e0574bb07eedd12da80312b064f9445817416c843fce68e0

netforceNIS.txt

Change Mirror Download
Vendor: Procom Technology, Inc.
Product: NetFORCE 800, v 4.02 M10 (Build 20)
Other Versions Vulnerable: unknown, vendor’s website sucks so I can’t tell
Vulnerability type: Information disclosure
Severity: Medium

* Software Information
--------------------
Model : NetFORCE 800
Version : 4.02 M10 (Build 20)
Vendor : Procom Technology, Inc.

Description:

NetFORCE’s operating system on the NAS includes the ability to send a diagnostic e-mail with a wealth of information to the technician to be able to diagnose problems without providing direct remote access. This diagnostic email includes output from various programs, statistical reports, and several file attachments.

One of these file attachments (passwd.nis) includes the NIS password map of any domain it is bound to, happily sending the entire domains fscking password hashes in the clear across the Internet over sendmail. This doesn’t impact you if you don’t use NIS as the other files that include user information “blank” out the password information.

NetFORCE sold its intellectual property to Sun and Sun uses the same systems to base their NAS solution off of. Because the NetFORCE website no longer has software versioning information, it is not possible to test on other versions or determine which versions are or are not vulnerable.
Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    0 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close