what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Cyberoam SSL VPN Client Plain-Text Storage

Cyberoam SSL VPN Client Plain-Text Storage
Posted May 27, 2010
Authored by Wasim Halani

Cyberoam SSL VPN Client version 1.0 suffers from a credential plain-text storage vulnerability.

tags | advisory
SHA-256 | 7c6a8124e4411e955439950da22cc1f0a3ceae972be47e2a49eaa7f3189835a0

Cyberoam SSL VPN Client Plain-Text Storage

Change Mirror Download
Cyberoam SSL VPN Client - Plain-text Storage of Username and Password

Vulnerability Summary:
Product: Cyberoam SSL VPN Client v1.0
Vendor: eLiteCore
Website: http://www.cyberoam.com/
Platform: Windows
Vulnerability Classification: Insecure Storage of User Credentials
Issue Fixed in Version: Cyberoam SSL VPN 9.6.0.78
Issue Discovered By: Wasim Halani (washal)
Organization: Network Intelligence India Pvt. Ltd.
(http://www.niiconsulting.com/)
Advisory Link: http://niiconsulting.com/vul/CyberoamSSLVPNClient.html
Date of Advisory: 26th May, 2010

Product Info:
"SSL VPN client is used for establishing remote connections in full access
mode. A remote user having an internet connection can download and install
SSL VPN Client. Once the client is installed, an encrypted tunnel is
established for secure access to the corporate network after providing user
credentials."

Vulnerability Description:
The Cyberoam SSL VPN client (CrSSL.exe) provides the user with an option to
save their credentials on the system for later use.

[IMG: http://niiconsulting.com/images/crssl-client-save-credentials.jpg ]

These details (username and password) are stored in the Windows registry
under the HKEY_CURRENT_USER hive.
The credentials are stored in plain-text in respective keys at the below
location
My Computer\HKEY_CURRENT_USER\Software\SslElite\CrSSL-Client
jalpassword=
jalusername=

[IMG: http://niiconsulting.com/images/plain-text-username-password.jpg ]

Vendor Communication:
27th October, 2009 - Vendor informed about vulnerability
28th October, 2009 - Confirmation of receipt of email
6th November, 2009 - Vendor confirms issue. To be considered a 'feature
request'.
3rd March, 2010 - Vendor informs us that the next firmware release will
fix the issue.
5th May, 2010 - Vendor confirms that the version 9.6.0.78 of the
Cyberoam SSL VPN and its corresponding SSL VPN client do not have the
vulnerability.

[IMG: http://niiconsulting.com/images/ssl-registry-fix.JPG ]

Solution:
Upgrade to the latest Cyberoam SSL VPN version of the, available on the
vendor website

Acknowledgements:
We would like to thank Mr. Rakesh Patel of eLitCore for the cooperation he
has shown in fixing the vulnerability.

--
Wasim Halani
Security Analyst
Network Intelligence India Pvt. Ltd.
http://www.niiconsulting.com/
Blog: http://www.niiconsulting.com/checkmate/
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close