vendor:
Canarytokens
by:
Benjamin Zink Loft, Gionathan Reale
7.5
CVSS
HIGH
Bypass Detection
287
CWE
Product Name: Canarytokens
Affected Version From: 2019-03-01
Affected Version To: 2019-03-01
Patch Exists: YES
Related CWE: 2019-9768
CPE: a:thinkst:canarytokens
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Linux
2019
Canarytokens 2019-03-01 – Detection Bypass
This exploit allows attackers to bypass detection of Canarytokens up to 2019-03-01 by unzipping the .docx file and checking the core.xml file for the presence of 'AAAAAAAAAAAAAAAA' and '2015-07-21' strings and filesize less than 170000 bytes.
Mitigation:
Ensure that the core.xml file is not modified and filesize is greater than 170000 bytes.