lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <00b901cc3669$a9f714f0$fde53ed0$@com>
Date: Wed, 29 Jun 2011 15:34:33 +0100
From: "NNT Support" <support@...ws.com>
To: <full-disclosure@...ts.grok.org.uk>
Cc: support@...nettechnologies.com
Subject: Resolved - NNT Change Tracker - Hard-Coded
	Encryption Key - Originally posted as
	http://seclists.org/fulldisclosure/2011/May/460

Background
-----------------

The product employs a portion of legacy code as referenced in the original
post. This is used for the product key and some database entries but whilst
the strength of the encryption being used here may be a problem for the NNT
licensing team, there is no genuine security risk for device data. This
portion of code has subsequently been replaced in Versions 5 and patches are
available from www.nntws.com

Change Tracker works on the principle of layered, multi-dimensional security
in line with the PCI DSS that it is commonly used to underpin. The secure
commissioning process should include standard lockdown and
access-restriction procedures for the Change Tracker server and database
server used for device and configuration data storage. Access security
should also  be complemented with monitoring using a SIEM solution such as
NNT Log Tracker, so any access to the Change Tracker server, the Change
Tracker console program or the database will be logged and alerted as
unusual activity. 

NNT take security of our customer systems extremely seriously. Anyone with
any concerns regarding best practise in Production System security should
contact us for further assistance. 

Regarding any vulnerabilities discovered by independent security researchers
in the future, we would prefer these are reported to us at support@...ws.com
before being published. This was not the case in this instance, delaying our
opportunity to respond. Thank you.
	
Company Homepage
------------------------------

http://www.newnettechnologies.com



Regards

NNT Support


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ