vendor:
Debian Linux
by:
Vladz
4,3
CVSS
MEDIUM
ptmx keystroke timing attack
200
CWE
Product Name: Debian Linux
Affected Version From: Debian 6.0.5
Affected Version To: Debian 6.0.5
Patch Exists: NO
Related CWE: CVE-2013-0160
CPE: o:debian:debian_linux:6.0.5
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2013
ptmx-su-pwdlen.sh
This PoC determines the password length of a local user who runs 'su -'. It is done thanks to the ptmx keystroke timing attack (CVE-2013-0160). It is tested on Debian 6.0.5 (kernel 2.6.32-5-amd64).
Mitigation:
Ensure that all running 'su' sessions are closed before using this PoC.