exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

HP-management.txt

HP-management.txt
Posted Apr 19, 2006
Authored by SRC Telindus

CompaqHTTPServer/9.9 and HP System Management

tags | advisory
SHA-256 | 4b1dab8814da47d54ea46f4645bed3644e6450a34f3eb537da81528a48ab4da8

HP-management.txt

Change Mirror Download
HP System Management Homepage Remote Unauthorized Access
--------------------------------------------------------

[Vulnerability]: Remote Authentication Bypass
[Product]: CompaqHTTPServer/9.9 HP System Management Homepage 2.1.3.132
and above
[Platform]: Microsoft® Windows® - Linux operating systems (IA32 and
Itanium Processor Family) - Tru64 UNIX v5.1A and above (according to HP)
[Reference(s)]: http://src.telindus.com/articles/hpsm_vulnerability.html
[Date]: Feb 20 2006
[Date of report to vendor]: Dec 12 2005

--------------------------------------------------------

[Vulnerability summary]: The HP System Management Homepage is a
web-based interface that consolidates and simplifies the management of
individual ProLiant and Integrity servers running Microsoft Windows or
Linux operating systems. By aggregating data from HP Insight Management
Agents and other management tools, the System Management Homepage
provides a secure and intuitive interface to review in-depth hardware
configuration and status data, performance metrics, system thresholds
and software version control information. The System Management Homepage
can also be used to access the HP Lights-Out Management processor on
ProLiant and Integrity servers.
(http://h18004.www1.hp.com/products/servers/management/agents/).
Access to HP System Management Homepage requires credentials posting ;
with the trust mode settled to "Trust All" configuration, this
authentication can be bypassed by sending a crafted URL. Therefore, a
potential aggressor can manage vulnerable host (modification of hardware
configuration, of tasks, of allowed IP range, shutdown, etc. and many
actions from there such as surrounding network attacks).

[Vulnerability impact]: Remote administration throught web management
interface (modification of hardware configuration, of tasks, of allowed
IP range, shutdown, etc., and many actions from there such as
surrounding network attacks)

----------------------------------------------------------------------

[Vendor fix]: None

[Vendor response]: [..] Set the Trust level to "Trust by Certificates".
This way only SIM servers with the appropriate level of access can do
any access with STE or SSO. This will not prevent an administrator from
logging into the SMH either remotely or locally. The SMH and SIM
documentation have more information on Trust Levels. The SMH Security
setup selection for trusts indicates that the only recommended and truly
secure trust level is by certificates.
http://www.hp.com/wwsolutions/misc/hpsim-helpfiles/mxhelp/mxportal/en/admin_security_about_secureTaskExecution.html#N1004B

(STE definition)

----------------------------------------------------------------------

[Reported by]: TELINDUS SRC (Grégoire DE BACKER)
Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    0 Files
  • 12
    Nov 12th
    0 Files
  • 13
    Nov 13th
    0 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close