Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Full-Disclosure] Nortel Networks Contivity VPN Client information leakage vulnerability |
|---|---|
| Date: | Wed, 10 Nov 2004 13:21:08 +0530 |
Name: User Account Enumeration in Nortel Contivity VPN Vendor: Nortel Networks Products Affected: Nortel Networks Contivity VPN Client Type: Remote User Account Enumeration Severity: Medium
II. Description 1. If a valid user name and an invalid password is given, the Contivity VPN Client displays "Login Failure due to: authentication failure" 2. If an invalid user name is given, the Contivity VPN Client displays "Login Failed: Please verify the entered login information is correct".
III. Impact The different error messages could enable a malicious person to guess valid user names on the Contivity VPN/Firewall, and then launch password-guessing attacks against these accounts.
IV. Solution This issue is resolved in Contivity VPN Client for Windows V5.01_030
V. About Network Intelligence India We're a leading provider of information security services and products. Our AuditPro suite of security assessment software provides comprehensive, policy-based security audits for Windows 2000, 2003, XP, Redhat Linux, Sun Solaris, Oracle and MS SQL Servers. For more information, visit us at http://www.nii.co.in
**** Happy Diwali AND Eid Mubarak! ****
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: [Full-Disclosure] Cross-Site-Scripting Vulnerability in Microsoft.com, offtopic |
|---|---|
| Next by Date: | [VulnWatch] Norton AntiVirus 2004/2005 Scripting Vulnerability Pt.3 (Includes PoC VBScript Code), Daniel Milisic |
| Previous by Thread: | [Full-Disclosure] Cross-Site-Scripting Vulnerability in Microsoft.com, Rafel Ivgi, The-Insider |
| Next by Thread: | [VulnWatch] Norton AntiVirus 2004/2005 Scripting Vulnerability Pt.3 (Includes PoC VBScript Code), Daniel Milisic |
| Indexes: | [Date] [Thread] [Top] [All Lists] |