Aladdin Knowledge Systems eToken PIN Extraction 漏洞

Aladdin Knowledge Systems eToken PIN Extraction 漏洞

漏洞ID 1105818 漏洞类型 设计错误
发布时间 2000-05-04 更新时间 2005-05-02
图片[1]-Aladdin Knowledge Systems eToken PIN Extraction 漏洞-安全小百科CVE编号 CVE-2000-0427
图片[2]-Aladdin Knowledge Systems eToken PIN Extraction 漏洞-安全小百科CNNVD-ID CNNVD-200005-026
漏洞平台 Windows CVSS评分 4.6
|漏洞来源
https://www.exploit-db.com/exploits/19894
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200005-026
|漏洞详情
AladdinKnowledgeSystemseToken设备存在漏洞,攻击者可以在不知道PIN所有者的情况下,通过复位EEPROM中PIN的物理手段访问设备的敏感信息。
|漏洞EXP
source: http://www.securityfocus.com/bid/1170/info

Alladin Knowledge Systems eToken is a USB smartcard-like device used for authentication, file integrity, and encryption. Access to the eToken device itself and entering the PIN number encoded in the eToken will grant authorization to a local user. 

The PIN number can be reset to the default value with the use of standard device programmers. This can be done by physically opening the eToken device (which can be done without leaving any trace or evidence of tampering) and copying the default PIN value to the location used to store either the user PIN or administrator PIN in the serial EEPROM.

https://github.com/offensive-security/exploit-database-bin-sploits/raw/master/bin-sploits/19894.zip
|参考资料

来源:BID
名称:1170
链接:http://www.securityfocus.com/bid/1170
来源:OSVDB
名称:3266
链接:http://www.osvdb.org/3266
来源:L0PHT
名称:20000504eTokenPrivateInformationExtractionandPhysicalAttack
链接:http://www.l0pht.com/advisories/etoken-piepa.txt

相关推荐: BroadBoard Message Board Multiple SQL Injection Vulnerabilities

BroadBoard Message Board Multiple SQL Injection Vulnerabilities 漏洞ID 1097826 漏洞类型 Input Validation Error 发布时间 2004-09-27 更新时间 2004…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享