vendor:
AIX
by:
Kingcope
7,5
CVSS
HIGH
Remote Root Hash Disclosure Exploit
N/A
CWE
Product Name: AIX
Affected Version From: IBM AIX 5.1
Affected Version To: IBM AIX 5.1
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: AIX
2010
AIXCOREDUMP.PL
AIXCOREDUMP.PL is an exploit that creates a coredump including the root user hash from /etc/security/passwd. The result file is scrambled and the user needs to seek for DES looking crypto keys. This exploit was successfully tested on IBM AIX 5.1 and discovered and exploited by Kingcope in July 2010.
Mitigation:
Ensure that the FTP server is configured securely and that the root user is not allowed to access the FTP server.