|
|
|
![]() |
Vulnerability Note VU#139139Air Messenger LAN Server (AMLServer) stores usernames and passwords in plaintextOverviewAir Messenger LAN Server (AMLServer) stores usernames and passwords in plaintext.I. DescriptionAMLServer for windows is a paging gateway that allows users on a TCP/IP LAN to communicate with mobile devices such as phones and pagers. Access to AMLServer's services is protected by a user authentication system that stores usernames and passwords in a plaintext file.II. ImpactIf an attacker can view the AMLServer password file (through direct access or another vulnerability), they can login as any AMLServer user.III. SolutionApply a patch when one is available. The CERT/CC is currently unaware of a practical solution to this problem.None.
Referenceshttp://www.securityfocus.com/bid/2882
Thanks to SNS Research for discovering this vulnerability. This document was written by Shawn Van Ittersum.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||