Full Disclosure mailing list archives
Arkeia Network Backup Client Remote Access
From: H D Moore <fdlist () digitaloffense net>
Date: Sun, 20 Feb 2005 14:42:20 -0600
Anyone able to connect to TCP port 617 can gain read/write access to the filesystem of any host running the Arkeia agent software. This appears to be an intentional design decision on the part of the Arkeia developers. A long-winded description of this issue, complete with screen shots, demonstration code, and packet captures can found online at: - http://metasploit.com/research/arkeia_agent/ -HD _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- Arkeia Network Backup Client Remote Access H D Moore (Feb 20)
- Re: Arkeia Network Backup Client Remote Access H D Moore (Feb 21)