A cookie, really?

Post Reply
User avatar
Pigeon
Posts: 18065
Joined: Thu Mar 31, 2011 3:00 pm

A cookie, really?

Post by Pigeon » Mon May 07, 2018 12:25 am

"An Argentinian security researcher named Ezequiel Fernandez has published a powerful new tool yesterday that can easily extract plaintext credentials for various DVR brands and grant attackers access to those systems, and inherently the video feeds they're supposed to record," reports Bleeping Computer. "The tool, named getDVR_Credentials, is a proof-of-concept for CVE-2018-9995, a vulnerability discovered by Fernandez at the start of last month, [affecting TBK DVR systems]. Fernandez discovered that by accessing the control panel of specific DVRs with a cookie header of 'Cookie: uid=admin,' the DVR would respond with the device's admin credentials in cleartext."

Link

Powerful tool? It is just sending a cookie. What a security screw up.

User avatar
Royal
Posts: 10566
Joined: Mon Apr 11, 2011 5:55 pm

Re: A cookie, really?

Post by Royal » Mon May 07, 2018 6:20 pm

hmmm, only this one cookie for this one device?

Looks like someone opened a can of worms.

User avatar
Pigeon
Posts: 18065
Joined: Thu Mar 31, 2011 3:00 pm

Re: A cookie, really?

Post by Pigeon » Mon May 07, 2018 7:38 pm

For that model, if not more, of the device.

User avatar
Bruno
Posts: 275
Joined: Fri Sep 07, 2018 7:08 am

Shut your mouth.. [privacy]

Post by Bruno » Tue Sep 18, 2018 8:11 am

If takes a lot more effort to be public...

[smarter not harder]


User avatar
Bruno
Posts: 275
Joined: Fri Sep 07, 2018 7:08 am

Approximate cause of your own injury..

Post by Bruno » Tue Sep 18, 2018 8:35 am


User avatar
Bruno
Posts: 275
Joined: Fri Sep 07, 2018 7:08 am

Fixed

Post by Bruno » Sat Sep 22, 2018 2:09 am

Bruno wrote:It takes a lot more effort to be public...

[smarter not harder]


Post Reply