======================================================================== = SecureCRT - Remote Command Execution = = Vendor Update: = http://www.vandyke.com/download/securecrt/index.html = = Affected Software: = SecureCRT V4.1, V4.0 (and probably lower) = = Public disclosure on November 23, 2004 ======================================================================== == Overview == In this time of responsible vulnerability disclosure, it's a little disturbing when a vendor acts on disclosed information but gives no recognition or even notification that an update has been created due to the information passed to them. This advisory is a little late, the update was posted to the vendor website last month. The only reason I know this, is because I asked and received a response. ------------------------------------------------------------------------ Brett, SecureCRT version 4.1.9 was released on Oct. 26, and is available for public download at the following location: http://www.vandyke.com/download/securecrt/index.html My apologies for not sending a special notice to you upon release. It was something that slipped off my radar. If you have any questions, please let us know. Thanks, Jake Devenport ------------------------------------------------------------------------ But enough of that, we know the game and still choose to play. SecureCRT installs a URL PROTOCOL handler into the registry, as "C:\Program Files\SecureCRT\SecureCRT.EXE" %1 This allows a user to click on a telnet:// link and have it opened from within their web browser. This 'telnet execution' can be automated through an html page such as