APP: PCAnywhere Administrator Login

This signature detects a PCAnywhere administrator login. Networks that allow PCAnywhere should use the rulebase to ignore admin login from administration PCs while alerting/blocking them from other sources.

Extended Description

Symantec pcAnywhere is shipped by default with a weak encryption scheme that is used to encrypt username and password transmittal. Therefore, usernames and password can be retrieved by anyone sniffing the network in between the host computer running pcAnywhere and the NT domain controller. Users of pcAnywhere can be authenticated with their NT domain username and password. In this case, the weakly encrypted transmitted authentication would be transmitted domain wide.

Affected Products

Symantec pcanywhere

References

BugTraq: 1093

CVE: CVE-2000-0300

Short Name
APP:PCANYWHERE:LOGIN-ADMIN
Severity
Info
Recommended
False
Recommended Action
None
Category
APP
Keywords
Administrator CVE-2000-0300 Login PCAnywhere bid:1093
Release Date
04/22/2003
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
Port
TCP/5631
False Positive
Rarely
Vendors

Symantec

CVSS Score

10.0

Found a potential security threat?