Blog : http://eromang.zataz.com
Twitter : / eromang
Timeline :
Vulnerability discovered by @kingcope
Vulnerability disclosed by @kingcope the 2012-12-01
Metasploit PoC the 2012-12-04
PoC provided by:
kingcope
bperry
sinn3r
Reference(s) :
Full Disclosure
Tectia Support
Affected versions :
All versions of Tectia SSH Server
Tested on Centos 5.8 x86 with:
SSH Tectia Server 6.3.2-33
Description :
This module exploits a vulnerability in Tectia SSH server for Unix-based platforms. The bug is caused by a SSH2_MSG_USERAUTH_PASSWD_CHANGEREQ request before password authentication, allowing any remote user to bypass the login routine, and then gain access as root.
More informations on http://eromang.zataz.com/2012/12/04/t...