[24785] in bugtraq

home help back first fref pref prev next nref lref last post

RE: [VulnWatch] NMRC Advisory - KeyManager Issue in ISS RealSecur

daemon@ATHENA.MIT.EDU (hellNbak)
Thu Mar 21 15:21:47 2002

Date: Thu, 21 Mar 2002 13:00:19 -0500 (EST)
From: hellNbak <hellnbak@nmrc.org>
To: "Rouland, Chris (ISSAtlanta)" <CRouland@iss.net>
Cc: <nmrcfolk@nmrc.org>, <bugtraq@securityfocus.com>,
        <vulnwatch@vulnwatch.org>, <focus-ids@securityfocus.com>
In-Reply-To: <DF3CC311E898D311A3670008C709BD2307F3064A@msgatl01.iss.net>
Message-ID: <Fuck.666.6.66.0203211256020.5207-100000@www.nmrc.org>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII

On Thu, 21 Mar 2002, Rouland, Chris (ISSAtlanta) wrote:
>
> Please confirm that you are able to exploit this, without root accesss to
> the IPSO box.


Chris, if I set up my own console, why would I need root access to the
IPSO box?  If I simply set my machine name to starscream and my user to
skank I am able to connect and push new keys generated by my console.

I am unsure why you would post that "NMRC is unable to confirm that this
can be exploited" without actually talking to me first.  I just tested it,
a second time, and yes, you can connect via the console and root access on
the Nokia box is not an issue.  The console connects to the control
chanell and allows me to push new keys down using the deployment wizard
which then allows me to set my new console as the "master controller" and
gather alerts, modify policied etc...


home help back first fref pref prev next nref lref last post