Encryption Weakness in Sun Sun AS 9.0_0.1 (build b02-p01)

看板Bugtraq作者時間18年前 (2007/08/22 23:23), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/1
Version Tested: Sun Application Server 9.0_0.1 (build b02-p01) Technical Description of the vulnerability: In the process of performing application security testing of software on Sun box, the Sun Admin Console was used to manipulate/change SSL Ciphers. Changes to the ORB listeners (SSL and SSL_MutualAuth) via the admin UI did not effectively change them in the software. Upon restarting the services/domain all of the SSL settings remain with the default - which enables all protocols and ciphers. Summary: Despite what is check/unchecked in the SUN admin UI of the AppServer, it doesn't actually affect the SSL Settings. Vulnerability: Broken linkage between Sun Admin Console and SSL Library/service. Tested using: Foundstone SSLDigger, SPI Server Analyzer, SSL Diagnostics and WireShark ___________________ Fred Donovan, CISSP Donovan Networks LLC 4701 Innovation Drive Lincoln, NE 68521 (402) 323-0730 (402) 730-5042 www.donovannetworks.com
文章代碼(AID): #16p5KD00 (Bugtraq)