Other nomination
VESTA Admin Takeover by exploiting bash $RANDOM limitations
Bash seeds its random variable by XORing microseconds and the process id into the timestamp without any bit shift, so only the low 20 bits vary and the seed lies within about a 12-day window of install time. Vesta control panel builds password-reset tokens from it, so an unauthenticated attacker can brute-force that range and predict the admin reset token.
Record
- Researcher
- Adrian Tiron and @adrian__t
- Published by
- FORTBRIDGE
- Date
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Adrian Tiron and @adrian__t, first published at the original source. Preserved copies are kept so the citation survives its host.