|
|
|
![]() |
Vulnerability Note VU#165099cryptcat does not encrypt data communications when -e command argument is usedOverviewWith certain options used, cryptcat does not encrypt network connections as expected.I. DescriptionCryptcat is an enhanced version of netcat that adds twofish encryption.If cryptcat is started in listen (server) mode binding a shell to a network port, cryptcat fails to enable encryption. Without encryption enabled on the server, cryptcat clients will not be able to connect. Furthermore, netcat clients can connect to the server port and communicate without encryption.
None.
References
Thanks to Eric Sheesley for reporting this vulnerability. This document was written by Shawn Van Ittersum.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||