[16210] in bugtraq
Re: Tumbleweed Worldsecure (MMS) BLANK 'sa' account password vuln
daemon@ATHENA.MIT.EDU (JD Conley)
Sat Aug 12 01:12:30 2000
Mime-Version: 1.0
Content-Type: text/plain; charset=iso-8859-1
Content-Transfer-Encoding: 7bit
Message-Id: <25C73987893CD211A3FD006008C02172615CBA@SERVER-CA>
Date: Fri, 11 Aug 2000 14:32:05 -0700
Reply-To: JD Conley <jdc@MALIBUBOATS.COM>
From: JD Conley <jdc@MALIBUBOATS.COM>
To: BUGTRAQ@SECURITYFOCUS.COM
> Tumbeweed refuses to acknowledge this vulnerability, which
> caused major outrage
> among my customers. Therefore, I have no choice but to go
> public about this
> vulnerability.
It seems the post to BUGTRAQ lit a fire under Tubleweed. In today's
technical bulletin they linked to a patch for the vulnerabilty here:
http://thompson.tumbleweed.com/NewKB/bulletin/UPFiles/sa-official.htm