Fw: Vulnerability in the way [email protected] handles MS-Logon Authentication.

[email protected] Thu, 4 May 2006 11:25:17 -0700
Newsgroups gmane.network.vnc.ultravnc.general
Message-ID <OF7D7817C1.F2C6A143-ON88257164.006503AA-88257164.00653128@2roads.com>
For feature requests and bug reports RC15 RC16. Please use the forum at http://forum.ultravnc.net/

This is a multipart message in MIME format.
--=_alternative 0065312588257164_=
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: quoted-printable

This was posted to Bugtraq the other day. Any comments?

-- Mark

----- Forwarded by Mark Gottschalk/2roads on 05/04/2006 11:23 AM -----

[email protected]=20
05/02/2006 11:40 PM


To
[email protected]
cc

Subject
Vulnerability in the way [email protected] handles MS-Logon Authentication.






AGR IT Advisory

May 2, 2006

AGR-ADV-2006-01



TITLE: Vulnerability in the way [email protected] handles MS-Logon=20
Authentication.



Overview



Deon Force discovered a vulnerability in Ultr@VNC 1.0.1 and earlier=20
versions with MS-Logon I and MS-Logon II authentication that may allow=20
attackers to crack the windows password directly from the intercepted=20
challenge response of MS-Logon traffic. This is due to the way Ultr@VNC=20
handle the MS-Logon authentication.



Description



Ultr@VNC (available at http://ultravnc.sourceforge.net/) is a free=20
software that can display the screen of another computer (via internet or=20
network) on your own screen. The program remotely controls the other PC=20
over any TCP/IP connection for administering and support.

While analyzing the MS-Logon authentication of Ultr@VNC, our team had=20
found that it is possible to crack the MS-Logon authentication. It uses a=20
simple algorithm to generate a response from the challenge sent by the VNC =

server to the VNC client and the username is sent in plain text.=20

Our team has made an update to the VNCrackX4 which is capable to crack the =

intercepted challenge response of the MS-Logon authentication. It is based =

on the original version of VNCrackX4 from phenoelit available for download =

at www.phenoelit.de/vnccrack/download.html. The updated version of=20
VNCrackX4 is or will be available at the same location.



Problems



The challenge response authentication process involve insecure and=20
reversible algorithm (XOR).

An attacker can extract the windows password from the intercepted=20
challenge // response.



Impact



Successfully sniffing the authentication session will compromise the=20
windows account used for authentication.

This account can further be used to compromise the system or other system=20
in the same domain or network.



Solution



We recommend not to use MS-Logon authentication method with Ultr@VNC until =

the algorithms used for authentication are improved.

A workaround to this vulnerability would be to use end-to-end encryption=20
for the communication between the server and the client. Implementing a=20
VPN solution could prevent an attacker from intercepting the session=20
authentication exchange.

Another solution is to use the DSM Plug-in available at=20
http://msrc4plugin.home.comcast.net/index.html provided that the key file=20
is kept secure.



Credit



This vulnerability was discovered and researched by Deon Force. It was=20
first reported to the Ultr@VNC team on 21 April 2006.



Copyright



This document is not to be edited or altered in any way without the=20
express written consent of AGR(B) Sdn. Bhd. If you wish to reprint the=20
whole or any part of this document, please email=20
no=5Fsp@[email protected] for permission. You may provide li=
nks=20
to this document from your web site, and you may make copies of this=20
document in accordance with international copyright laws.=20



Disclaimer



The information within this document may change without notice. Use of=20
this information constitutes acceptance for use in an AS IS condition.=20
There are NO warranties, implied or otherwise, with regard to this=20
information or its use. Any use of this information is at the user's risk. =

In no event shall the author/distributor be held liable for any damages=20
whatsoever arising out of or in connection with the use or spread of this=20
information.



About Deon Force



Deon Force is a team of security experts working in collaboration with=20
Asia Global Risk.



About Asia Global Risk



Asia Global Risk is a risk management company providing a wide range of=20
security services, including IT security.

Website: http://www.asia-global-risk.com



Revisions:



Version 0.1 April 21 -2006 ? Draft version.

Version 1.0 May 2 -2006 ? First Public Version.

An updated version of this document may be found at this address:=20
http://www.asia-global-risk.com/IT/AGR=5FIT=5FADV=5F2006-01-VNC.pdf


ForwardSourceID:NT000CF1FE=20
--=_alternative 0065312588257164_=
Content-Type: text/html; charset="ISO-8859-1"
Content-Transfer-Encoding: quoted-printable


<br><font size=3D2 face=3D"sans-serif">This was posted to Bugtraq the other
day. Any comments?</font>
<br>
<br><font size=3D2 face=3D"sans-serif">-- Mark</font>
<br>
<br><font size=3D1 color=3D#800080 face=3D"sans-serif">----- Forwarded by M=
ark
Gottschalk/2roads on 05/04/2006 11:23 AM -----</font>
<br>
<table width=3D100%>
<tr valign=3Dtop>
<td width=3D40%><font size=3D1 face=3D"sans-serif"><b>gdehanot@asia-global-=
risk.com</b>
</font>
<p><font size=3D1 face=3D"sans-serif">05/02/2006 11:40 PM</font>
<br>
<td width=3D59%>
<table width=3D100%>
<tr>
<td>
<div align=3Dright><font size=3D1 face=3D"sans-serif">To</font></div>
<td valign=3Dtop><font size=3D1 face=3D"sans-serif">[email protected]=
om</font>
<tr>
<td>
<div align=3Dright><font size=3D1 face=3D"sans-serif">cc</font></div>
<td valign=3Dtop>
<tr>
<td>
<div align=3Dright><font size=3D1 face=3D"sans-serif">Subject</font></div>
<td valign=3Dtop><font size=3D1 face=3D"sans-serif">Vulnerability in the way
[email protected] handles MS-Logon Authentication.</font></table>
<br>
<table>
<tr valign=3Dtop>
<td>
<td></table>
<br></table>
<br>
<br>
<br><font size=3D2><tt>AGR IT Advisory<br>
<br>
May 2, 2006<br>
<br>
AGR-ADV-2006-01<br>
<br>
<br>
<br>
TITLE: Vulnerability in the way [email protected] handles MS-Logon Authenticat=
ion.<br>
<br>
<br>
<br>
Overview<br>
<br>
<br>
<br>
Deon Force discovered a vulnerability in Ultr@VNC 1.0.1 and earlier versions
with MS-Logon I and MS-Logon II authentication that may allow attackers
to crack the windows password directly from the intercepted challenge respo=
nse
of MS-Logon traffic. This is due to the way Ultr@VNC handle the MS-Logon
authentication.<br>
<br>
<br>
<br>
Description<br>
<br>
<br>
<br>
Ultr@VNC (available at http://ultravnc.sourceforge.net/) is a free software
that can display the screen of another computer (via internet or network)
on your own screen. The program remotely controls the other PC over any
TCP/IP connection for administering and support.<br>
<br>
While analyzing the MS-Logon authentication of Ultr@VNC, our team had found
that it is possible to crack the MS-Logon authentication. It uses a simple
algorithm to generate a response from the challenge sent by the VNC server
to the VNC client and the username is sent in plain text. <br>
<br>
Our team has made an update to the VNCrackX4 which is capable to crack
the intercepted challenge response of the MS-Logon authentication. It is
based on the original version of VNCrackX4 from phenoelit available for
download at www.phenoelit.de/vnccrack/download.html. The updated version
of VNCrackX4 is or will be available at the same location.<br>
<br>
<br>
<br>
Problems<br>
<br>
<br>
<br>
The challenge response authentication process involve insecure and reversib=
le
algorithm (XOR).<br>
<br>
An attacker can extract the windows password from the intercepted challenge
// response.<br>
<br>
<br>
<br>
Impact<br>
<br>
<br>
<br>
Successfully sniffing the authentication session will compromise the windows
account used for authentication.<br>
<br>
This account can further be used to compromise the system or other system
in the same domain or network.<br>
<br>
<br>
<br>
Solution<br>
<br>
<br>
<br>
We recommend not to use MS-Logon authentication method with Ultr@VNC until
the algorithms used for authentication are improved.<br>
<br>
A workaround to this vulnerability would be to use end-to-end encryption
for the communication between the server and the client. Implementing a
VPN solution could prevent an attacker from intercepting the session authen=
tication
exchange.<br>
<br>
Another solution is to use the DSM Plug-in available at http://msrc4plugin.=
home.comcast.net/index.html
provided that the key file is kept secure.<br>
<br>
<br>
<br>
Credit<br>
<br>
<br>
<br>
This vulnerability was discovered and researched by Deon Force. It was
first reported to the Ultr@VNC team on 21 April 2006.<br>
<br>
<br>
<br>
Copyright<br>
<br>
<br>
<br>
This document is not to be edited or altered in any way without the express
written consent of AGR(B) Sdn. Bhd. If you wish to reprint the whole or
any part of this document, please email no=5Fsp@m=5Fsupport@asia-global-ris=
k.com
for permission. You may provide links to this document from your web site,
and you may make copies of this document in accordance with international
copyright laws. <br>
<br>
<br>
<br>
Disclaimer<br>
<br>
<br>
<br>
The information within this document may change without notice. Use of
this information constitutes acceptance for use in an AS IS condition.
There are NO warranties, implied or otherwise, with regard to this informat=
ion
or its use. Any use of this information is at the user's risk. In no event
shall the author/distributor be held liable for any damages whatsoever
arising out of or in connection with the use or spread of this information.=
<br>
<br>
<br>
<br>
About Deon Force<br>
<br>
<br>
<br>
Deon Force is a team of security experts working in collaboration with
Asia Global Risk.<br>
<br>
<br>
<br>
About Asia Global Risk<br>
<br>
<br>
<br>
Asia Global Risk is a risk management company providing a wide range of
security services, including IT security.<br>
<br>
Website: http://www.asia-global-risk.com<br>
<br>
<br>
<br>
Revisions:<br>
<br>
<br>
<br>
Version 0.1 April 21 -2006 &#8211; Draft version.<br>
<br>
Version 1.0 May 2 -2006 &#8211; First Public Version.<br>
<br>
An updated version of this document may be found at this address: http://ww=
w.asia-global-risk.com/IT/AGR=5FIT=5FADV=5F2006-01-VNC.pdf<br>
<br>
</tt></font>
<br><font size=3D2 color=3Dwhite face=3D"sans-serif">ForwardSourceID:NT000C=
F1FE
&nbsp; &nbsp;</font>
--=_alternative 0065312588257164_=--


-------------------------------------------------------
Using Tomcat but need to do more? Need to support web services, security?
Get stuff done quickly with pre-integrated technology to make your job easier
Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo
http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642