J-Security Center

Title: Borland/Inprise Interbase Backdoor Password Vulnerability

Severity: HIGH

Description:

Interbase is an open source relational database offered by Borland Inprise Corporation.

Interbase contains a backdoor user account and password called "LOCKSMITH". When accessed this account will eliminate all implemented security allowing full control of any database and contents within the database, this level of access will allow any function to be performed including modification of objects, root access and execution of arbitrary functions. "LOCKSMITH" is hard coded in the database engine and is located in the jrd/pwd.h header.

Successful exploitation of this vulnerability will lead to complete compromise of the host.

**Update: This vulnerability is also reported to affect Firebird 0.9-3 and earlier.

Affected Products:

  • Borland/Inprise Interbase 4.0.0
  • Borland/Inprise Interbase 5.0.0
  • Borland/Inprise Interbase 6.0.0
  • Borland/Inprise Interbase 6.0.1
  • Firebird Firebird 0.9.0 -3

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.