SecuriTeam"! - Trend Micro Products Web Management Authentication Bypass(情報元のブックマーク数)

ウイルスバスターCorp版のWeb管理画面の認証を回避できる脆弱性が存在するそうです。

ランダムセッショントークンで1秒ごとに作られる?ので、ブルートフォースで認証が解けるみたいです。

Vulnerable Systems:


The vulnerability is caused by insufficient entropy being used to create a random session token for identifying an authenticated manager using the web management console. The entropy in the session token comes solely from the system time when the real manager logs in with a granularity of one second. This can be exploited to impersonate a currently logged on manager by brute forcing the authentication token.

Successful exploitation further allows execution of arbitrary code via manipulation of the configuration.

Trend Micro Products Web Management Authentication Bypass