lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <40313.38.112.183.231.1187784590.squirrel@webmail.donovannetworks.com>
Date: Wed, 22 Aug 2007 05:09:50 -0700 (PDT)
From: <fred@...ovannetworks.com>
To: <bugtraq@...urityfocus.com>
Subject: Encryption Weakness in Sun Sun AS 9.0_0.1 (build b02-p01)

Version Tested:
Sun Application Server 9.0_0.1 (build b02-p01)

Technical Description of the vulnerability:
In the process of performing application security testing of software on
Sun box, the Sun Admin Console was used to manipulate/change SSL Ciphers.
Changes to the ORB listeners (SSL and SSL_MutualAuth) via the admin UI did
not
effectively change them in the software. Upon restarting the
services/domain all of the SSL settings remain with the default - which
enables all protocols and ciphers.
Summary: Despite what is check/unchecked in the SUN admin UI of the
AppServer, it doesn't actually affect the SSL Settings.

Vulnerability: Broken linkage between Sun Admin Console and SSL
Library/service.

Tested using:
Foundstone SSLDigger, SPI Server Analyzer, SSL Diagnostics and WireShark

___________________
Fred Donovan, CISSP
Donovan Networks LLC
4701 Innovation Drive
Lincoln, NE  68521
(402) 323-0730
(402) 730-5042
www.donovannetworks.com


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ