Bugtraq mailing list archives

Sonicwall diag tool includes VPN credentlials


From: Milton Lopez <mlopez () iattc org>
Date: 30 Jul 2004 21:46:07 -0000



Our Sonicwall Pro 300 firewall appliance includes a diagnostic tool called "Tech Support Report", which dumps the 
current configuration info to a plain text file. I have been asked by Sonicwall personnel to email this file as an 
attachment during several tech. support calls, without any additional warning or explanation. One of the items included 
in the report is a plain-text copy of the Shared Secret used for authenticating VPN users. Unless everything I've read 
about protecting this kind of information is suddenly not true, sending unprotected shared secrets to anyone via email 
is very bad idea. I also doubt that tech. support personnel need this in most cases and, if they do, the customer 
should be notified and asked for it explicitly.


Current thread: