|
|
| |
| Big Brother is designed to let administrators see how the network is doing in near real-time, from any web browser. A vulnerability in the product leaks possibly-sensitive information such as allowing to identify whether a certain file exists on the hard-drive, as well as determine user ids on the BBDISPLAY server (this information can later be used to launch a password brute-force attack). |
| |
Credit:
The information has been provided by Loki.
|
| |
Exploit:
http://www.example.com/cgi-bin/bb-hist.sh?HISTFILE=/home/*
Patch:
A patch is available from:
http://bb4.com/incident.nov21
|
|
|