Quantcast
Channel: Files Date: 2018-11-28 to 2018-11-29 ≈ Packet Storm
Viewing all articles
Browse latest Browse all 20

Unitrends Enterprise Backup bpserverd Privilege Escalation

$
0
0
It was discovered that the Unitrends bpserverd proprietary protocol, as exposed via xinetd, has an issue in which its authentication can be bypassed. A remote attacker could use this issue to execute arbitrary commands with root privilege on the target system. This is very similar to exploits/linux/misc/ueb9_bpserverd however it runs against the localhost by dropping a python script on the local file system. Unitrends stopped bpserverd from listening remotely on version 10.

Viewing all articles
Browse latest Browse all 20

Latest Images

Trending Articles





Latest Images