vendor:
HP Tru64 UNIX
by:
Andrea Purificato
7.5
CVSS
HIGH
Remote Secure Shell user enumeration exploit
200
CWE
Product Name: HP Tru64 UNIX
Affected Version From: HP Tru64 UNIX v5.1B-4
Affected Version To: HP Tru64 UNIX v5.1B-3
Patch Exists: NO
Related CWE: CVE-2007-2791
CPE: o:hp:tru64_unix:5.1b-4
Platforms Tested:
2007
HP Tru64 Remote Secure Shell user enumeration exploit
This is a Perl script that exploits a vulnerability (CVE-2007-2791) in HP Tru64 UNIX versions 5.1B-4 and 5.1B-3. It allows an attacker to enumerate users on a remote system using the Secure Shell (SSH) protocol. The script first grabs the banner from the target system using telnet, then uses SSH to time the response when trying to authenticate with different usernames. By comparing the response times, the attacker can determine which usernames exist on the target system.
Mitigation:
Upgrade to a patched version of HP Tru64 UNIX.