BLUE MOON SECURITY ADVISORY 2008-04

Title:Weak password protection in multiple Internet Cafe products
Severity:Low
Reporter:Blue Moon Consulting
Products:
  1. VDC iNCM beta 9
  2. 24h NetCafe 6.2.0.5
Fixed in:--

Description

The products mentioned in this advisory stores users' passwords in plain text in their databases. If an attacker is able to obtain the database file, these sensitive data will be compromised. Advisory BMSA-2008-02 detailed a directory traversal vulnerability (moderate severity) in VDC iNCM which, when coupled with this vulnerability (low severity), would result in an elevation of severity to critical.

These products also ignore case sensitivity and only allow limited charsets in passwords. This greatly reduces the search space of a brute-forcing prorgam, making it more likely for an attacker to find a working password.

Workaround

There is no workaround.

Fix

There is no fix at the moment. Customers are advised to contact the vendor directly.

Disclosure

Blue Moon Consulting adapts RFPolicy v2.0 in notifying vendors.

Initial vendor contact:
 May 13, 2008: alert sent to incm102006@yahoo.com and hoangl@24h.com.vn
Vendor response:
 May 14, 2008: acknowledgement received from incm102006@yahoo.com
Public disclosure:
 May 20, 2008
Exploit code:no exploit code needed

Disclaimer

The information provided in this advisory is provided "as is" without warranty of any kind. Blue Moon Consulting Co., Ltd disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. Your use of the information on the advisory or materials linked from the advisory is at your own risk. Blue Moon Consulting Co., Ltd reserves the right to change or update this notice at any time.