The OpenNET Project
 
Search (keywords):  SOFT ARTICLES TIPS & TRICKS SECURITY
LINKS NEWS MAN DOCUMENTATION


Vulnerability in IBM access


<< Previous INDEX Search src / Print Next >>
Date: 26 Jul 2005 09:46:44 -0000
From: [email protected]
To: [email protected]
Subject: Vulnerability in IBM access
X-Virus-Scanned: antivirus-gw at tyumen.ru

Hello, 

I would like to make to Bugtraq knowledge the existence of a security vulnerability in IBM access software. IBM access is vulnerable to a Shared Section vulnerability. The processes QCWLICON.exe and QCTRAY.exe have the section \BaseNamedObjects\QCONDB with invalid rights which allows everyone to read the configuration of all connections and to write arbitrary data to create a dos against the application. 
This could be shown with the Process Explorer tool by sysinternal and used by the ListSS, DumpSS and TestSS tools written by C Cerrudo. 
Regards, 

Sylvain ROGER
Security Consultant
http://www.solucom.fr


<< Previous INDEX Search src / Print Next >>



Партнёры:
PostgresPro
Inferno Solutions
Hosting by Hoster.ru
Хостинг:

Закладки на сайте
Проследить за страницей
Created 1996-2024 by Maxim Chirkov
Добавить, Поддержать, Вебмастеру