about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , screen 4.0.3 Local Authentication Bypass Vulnerability



2007-06-04 screen 4.0.3 Local Authentication Bypass Vulnerability
Rated as : High Risk

                     _   _ _____ _     ___ _____ _   _
                   / / / / ____/ /   /  _/_  __/ / / /
                  / /_/ / __/ / /    / /  / / / /_/ /
                 / __  / /___/ /____/ /  / / / __  /
                /_/ /_/_____/_____/___/ /_/ /_/ /_/
                           Helith - 0815
--------------------------------------------------------------------------------


Author: Rembrandt
Date: Known since somewhere in &cant_remember
Affected Software: screen <= 4.0.3
Type: Local
Type: Authentication Bypass

Greets go to: Helith and all affiliated People, t3c0, levent, str0ke,
              hdm, The EOF-Crew, rrlf, herm1t, Solar Designer, softxor,
              Packetstorm, FeFe, kscope, Zarathu, f0rg3, Mr. Joern Alles

Disrespect goes to: A Bank [/]
                    And others included into this case...

Personal note: I wanna get MY STUFF BACK!
               This is the last "diplomatic" attemp made
directly.
               Contact me if you`re interested into a deescalation.
               Nobody is interested into making the things even more
complicated
               or? So make your choice. And you better hurry...
               And this is no blackmailing attemp but others may decide
for you
               if you don`t do it.
               IMPORTENT: Turn your brain "ON" this time.
--------------------------------------------------------------------------------

I didn`t found a Adv. related to this so I decided to write one. :]

screen is vulnerable to a authentication bypass which allows local
attackers
to gain system access in case screen was locked with a Password.

It has been tested on OpenBSD 4.1 + screen 4.0.3 on x86.

How to reproduce:

Lock screen using ctrl+x
Choose a Password
Confirm the Password

Screen asks for a Password to unlock the screen.
Just press ctrl+c and it displays "Getpass error".
2 seconds later the screen is unlocked and you`ve access.


Have fun!

securitydot.net - 2007-06-04

Advertising

Copyright 2007, SecurityDot
Sun, 08 Nov 2009 21:29:50 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
preesx 3gp xxx hi zeroboard. Los invaso protection Sulla.Com Rambha Nud Gambar sas Los invaso dream pinb mambo Remo Resin 3.0. proftp 1.2 XNXX.89.co www.segou1 senetman 200 /compo Www.newsex sexy blomd WWWSEX.COM amerikasex www.hwoool apache 2.0 200 /compo Www.tv5com iifamoqyvy freeones www.123923 news for c alstra lo228l shopadmin. www.jogoso desi kahan t601t sex arapic blackice-a LinkEX 200 /compo Womensex avjaganath rumba www.xingha sex ladies www.jscctv mambo Remo guest book www.colegi mambo Remo IceWarp We