J-Security Center

Title: Arkeia Server Static Salt Weak Password Vulnerability

Severity: HIGH

Description:

Arkeia Server is an enterprise-based backup software solution distributed and maintained by Knox Software.

A problem with Arkeia Server has been discovered that could allow a user with access to encrypted passwords to gain elevated privileges, including Arkeia environment root access.

The problem is due to the salting of the password when the encrypted hash is generated. Arkeia makes use of the unix crypt() function when a password is added to the system, placing the output of the crypt() function in the password file.

When the password is salted, a static salt is used for every password entered in the password file. This salt is typically a the character string "n3." In the event of a user gaining access to the password file and stealing the passwords, this information could be useful in a brute force password crack attempt, or though means of cryptanalysis.

This problem is compounded by the fact that the maximum length for an Arkeia password is 8 characters and that the password file '/dbase/f3sec/usr.lst' is world readable.

Affected Products:

  • Knox Software Arkeia 4.0.0
  • Knox Software Arkeia 4.1.0
  • Knox Software Arkeia 4.2.0
  • Knox Software Arkeia 5.2.0
  • Knox Software Arkeia 5.3.0
  • Knox Software Arkeia Server 4.2.8 -2
  • S.u.S.E. Linux 6.2.0

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.