SecureCRT contains a flaw related to password storage. The issue is due to the program using a weak encoding method to protect passwords, rather than a cryptographically sound scheme. By manipulating an .ini file to change the username, an attacker can then connect to a server with the intention of receiving an 'invalid password' message. This message contains an obscured copy of the password in cleartext, which can be reversed using commonly available programs such as 'Asterisk Key.
Disclosure Timeline:
Disclosure Date :2013-02-28
Exploit Publish Date :2013-02-28