Tribal Voice PowWow Password...

- AV AC AU C I A
发布: 1999-10-19
修订: 2025-04-13

PowWow is a network communications tool by Tribal Voice, similar to ICQ or AOL Instant Messenger. PowWow contains several vulnerabilities whereby a user's PowWow password can be obtained by an attacker. The first vulnerability involves the powwow.ini file, where a user's name and password are stored in plaintext. This file can be found at C:\windows\powwow.ini on Win9x platforms and at C:\winnt\powwow.ini on NT machines. The entries look like this: LOCALNAME:user @ server.com LOCALPASS:user's_password The second vulnerability is related to how PowWow transmits the password to the PowWow server to authenticate the user in various operations, mostly related to listings in the PowWow white pages. The password is sent via the URL, in plaintext, meaning it is accessible visibly from the address bar or (later) the history list of the browser being used, as well as via sniffing at any intermediary point on the network. For example, the URL used to remove oneself from the White pages...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息