SV: PIX Privilege Escalation Vulnerability

"Jan Nielsen" <[email protected]> Thu, 24 Jan 2008 22:18:50 +0100
Newsgroups gmane.comp.security.vulnerabilities
Message-ID <[email protected]>
Does not seem to work on ASA 8.0(2)

Regards
Jan

-----Oprindelig meddelelse-----
Fra: [email protected] [mailto:[email protected]] =
P=E5
vegne af [email protected]
Sendt: 24. januar 2008 04:42
Til: [email protected]
Emne: PIX Privilege Escalation Vulnerability

Back in May of last year I started doing research on any possible =
security
flaws that exist in the Pix/ASA Finesse operating System, versions 7.1 =
and
7.2. I discovered that a design flaw that was previously unknown in =
Finesse
will allow a level 0 user to escalate their privilege to level 15. I =
believe
the vulnerability may originate in the local authentication service, =
thus
not being possible to exploit when Radius and TACACS is implemented.
Implementing AAA in any other way that keeps the passwords locally =
defined
seems to have no affect on the vulnerability. I have been able to =
repeatedly
bypass the privilege-exec login both locally, through the console and
remotely, through a telnet connection. After many attempts I have found =
that
the SSH service does not seem to suffer from the vulnerability.=20
	I am now going to go over the simplicity of the exploit and I will
be releasing a white paper hopefully sooner than later on the specifics =
of
the underlying cause. Once a user has logged on to the user-exec =
(level0) of
the device they will then be able to proceed with the <enable> command =
which
should give you a login prompt. At this prompt if you move your cursor
forward with a space or character(it doesn't matter if there are more =
then
one), and then proceed to delete any spaces or characters, by holding =
down
the backspace a second after deleting the last character it should
immediately drop you into level 15 privilege-exec mode. This attack was
originally performed on a PIX 515E running version 7.2 of Finesse. I =
will be
posting all updates regarding this exploit as they come, and I apologize =
for
it taking so long to release this information.

Terry B Bunn
LunarTEkINT Labs=20


!DSPAM:326,4798c3b8471831356118003!