Thursday, September 6, 2007

Cisco Adaptive Security Appliance Password Logging Weakness

A weakness has been reported in Cisco Adaptive Security Appliance (ASA), which can be exploited by malicious people to disclose sensitive information.

The weakness is caused due to Cisco ASA not correctly sanitising log messages of the "test aaa-server" command before sending them to syslog. This can lead to the disclosure of sensitive information like usernames and passwords.

The error occurs when a user with privilege level 15 or above executes the "test aaa-server" command and logging level 5 (notifications) is activated.

Solution:
Update to 8.0.2.11 for the 8.0 train, 7.2.2.34 for the 7.2 train, 7.1.2.61 for the 7.1 train, and 7.0.7.1 for the 7.0 train.

1 comment:

Anonymous said...

I've just recently downloaded Mt4 Protect and wanted to tell you guys about my experience with it.
I was worried about all the Metatrader Malware out there at the moment as I heard you can get them from downloading Expert Advisors from the internet.
While I don't download decompiled experts the last thing I want is some hacker getting my account details and draining my trading account as I have built it up into quite a bit of $$$. That's why I purchased MT4 protect so it can stop my pc from getting attacked. I think the price is well worth the protection I will receive
I got a copy at [url=http://www.mt4protect.com/] http://www.mt4protect.com/ [/url] via paypal and my product code was sent to me within 4 hours.
I installed it and its awesome! It works in the system tray and scans my computer in real time to detect any attacks.
The EA optimization tool is so great - you can allocate more memory to your MT4 terminal so your trades get executed faster! There are also heaps of registry tweaks and cleanup features that have speeded up my Windows 2000 PC.
With hackers and virus attacks hitting Forex traders all the time now I definitely think that MT4 Protect is a worthwhile investment.