Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Vuln-Dev
[Top] [All Lists]

Re: [Full-disclosure] ZDI-07-069: CA BrightStor ARCserve Backup Message

Subject: Re: [Full-disclosure] ZDI-07-069: CA BrightStor ARCserve Backup Message Engine Insecure Method Expos
Date: Wed, 28 Nov 2007 03:32:51 +0000

it is so amazing that the vendor's advisory has been released more than one 
month ago, (see my advisory of a similar vul at 
http://ruder.cdut.net/blogview.asp?logID=221), and another thing is that I have 
tested my reported vul again after CA's patch released one month ago, but in 
fact they have not fixed it!! I report it again to CA but there is no response, 
I guess CA is making an international joke with us:), or because this product 
is sooooooooo bad that they will not support it any more?
 
welcome to my blog:http://ruder.cdut.net
 
From: zdi-disclosures@3com.com> To: full-disclosure@lists.grok.org.uk; 
bugtraq@securityfocus.com> Date: Mon, 26 Nov 2007 16:10:30 -0600> Subject: 
[Full-disclosure] ZDI-07-069: CA BrightStor ARCserve Backup Message Engine 
Insecure Method Exposure Vulnerability> > ZDI-07-069: CA BrightStor ARCserve 
Backup Message Engine Insecure Method > Exposure Vulnerability> 
http://www.zerodayinitiative.com/advisories/ZDI-07-069.html> November 26, 
2007> > -- CVE ID:> CVE-2007-5328> > -- Affected Vendor:> Computer 
Associates> > -- Affected Products:> BrightStor ARCserve Backup r11.5> 
BrightStor ARCserve Backup r11.1> BrightStor ARCserve Backup r11.0> 
BrightStor Enterprise Backup r10.5> BrightStor ARCserve Backup v9.01> > -- 
TippingPoint(TM) IPS Customer Protection:> TippingPoint IPS customers have 
been protected against this> vulnerability by Digital Vaccine protection 
filter ID 5144. > For further product information on the TippingPoint IPS:> > 
http://www.tippingpoint.com > > -- Vulnerabil
 ity Details:> This vulnerability allows attackers to arbitrarily access and 
modify the> file system and registry of vulnerable installations of Computer> 
Associates BrightStor ARCserve Backup. Authentication is not required> to 
exploit this vulnerability.> > The specific flaws exists in the Message Engine 
RPC service which> listens by default on TCP port 6504 with the following 
UUID:> > 506b1890-14c8-11d1-bbc3-00805fa6962e> > The service exposes a number 
of insecure method calls including: 0x17F,> 0x180, 0x181, 0x182, 0x183, 0x184, 
0x185, 0x186, 0x187, 0x188, 0x189,> 0x18A, 0x18B, and 0x18C. Attackers can 
leverage these methods to> manipulate both the file system and registry which 
can result in a> complete system compromise.> > -- Vendor Response:> Computer 
Associates has issued an update to correct this vulnerability.> More details 
can be found at:> > 
http://supportconnectw.ca.com/public/storage/infodocs/basb-secnotice.asp> > -- 
Disclosure Timeline:> 2007.01.12 - Vulnerabi
 lity reported to vendor> 2007.11.26 - Coordinated public release of advisory> 
-- Credit:> This vulnerability was discovered by Tenable Network Security.> > 
-- About the Zero Day Initiative (ZDI):> Established by TippingPoint, The Zero 
Day Initiative (ZDI) represents > a best-of-breed model for rewarding security 
researchers for responsibly> disclosing discovered vulnerabilities.> > 
Researchers interested in getting paid for their security research> through the 
ZDI can find more information and sign-up at:> > 
http://www.zerodayinitiative.com> > The ZDI is unique in how the acquired 
vulnerability information is used.> 3Com does not re-sell the vulnerability 
details or any exploit code.> Instead, upon notifying the affected product 
vendor, 3Com provides its> customers with zero day protection through its 
intrusion prevention> technology. Explicit details regarding the specifics of 
the> vulnerability are not exposed to any parties until an official vendor> 
patch is publicly av
 ailable. Furthermore, with the altruistic aim of> helping to secure a broader 
user base, 3Com provides this vulnerability> information confidentially to 
security vendors (including competitors)> who have a vulnerability protection 
or mitigation product.> > CONFIDENTIALITY NOTICE: This e-mail message, 
including any attachments,> is being sent by 3Com for the sole use of the 
intended recipient(s) and> may contain confidential, proprietary and/or 
privileged information.> Any unauthorized review, use, disclosure and/or 
distribution by any > recipient is prohibited. If you are not the intended 
recipient, please> delete and/or destroy all copies of this message regardless 
of form and> any included attachments and notify 3Com immediately by contacting 
the> sender via reply e-mail or forwarding to 3Com at postmaster@3com.com. > 
_______________________________________________> Full-Disclosure - We believe 
in it.> Charter: http://lists.grok.org.uk/full-disclosure-charter.html> Hosted 
 and sponsored by Secunia - http://secunia.com/
_________________________________________________________________
用 Live Search 搜尽天下资讯!
http://www.live.com/?searchOnly=true
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
<Prev in Thread] Current Thread [Next in Thread>