SV: PIX Privilege Escalation Vulnerability
"Jan Nielsen" <[email protected]> Thu, 24 Jan 2008 22:18:50 +0100
| Newsgroups | gmane.comp.security.vulnerabilities |
|---|---|
| Message-ID | <[email protected]> |
Does not seem to work on ASA 8.0(2) Regards Jan -----Oprindelig meddelelse----- Fra: [email protected] [mailto:[email protected]] = P=E5 vegne af [email protected] Sendt: 24. januar 2008 04:42 Til: [email protected] Emne: PIX Privilege Escalation Vulnerability Back in May of last year I started doing research on any possible = security flaws that exist in the Pix/ASA Finesse operating System, versions 7.1 = and 7.2. I discovered that a design flaw that was previously unknown in = Finesse will allow a level 0 user to escalate their privilege to level 15. I = believe the vulnerability may originate in the local authentication service, = thus not being possible to exploit when Radius and TACACS is implemented. Implementing AAA in any other way that keeps the passwords locally = defined seems to have no affect on the vulnerability. I have been able to = repeatedly bypass the privilege-exec login both locally, through the console and remotely, through a telnet connection. After many attempts I have found = that the SSH service does not seem to suffer from the vulnerability.=20 I am now going to go over the simplicity of the exploit and I will be releasing a white paper hopefully sooner than later on the specifics = of the underlying cause. Once a user has logged on to the user-exec = (level0) of the device they will then be able to proceed with the <enable> command = which should give you a login prompt. At this prompt if you move your cursor forward with a space or character(it doesn't matter if there are more = then one), and then proceed to delete any spaces or characters, by holding = down the backspace a second after deleting the last character it should immediately drop you into level 15 privilege-exec mode. This attack was originally performed on a PIX 515E running version 7.2 of Finesse. I = will be posting all updates regarding this exploit as they come, and I apologize = for it taking so long to release this information. Terry B Bunn LunarTEkINT Labs=20 !DSPAM:326,4798c3b8471831356118003!