eTrust Intrusion Detection System (formerly SessionWall-3) uses weak encryption (XOR) to store administrative passwords in the registry, which allows local users to easily decrypt the passwords.
Link | Tags |
---|---|
http://www.securityfocus.com/templates/archive.pike?list=1&msg=Pine.BSO.4.21.0006072124320.28062-100000%40bearclaw.bogus.net | mailing list |
http://www.securityfocus.com/bid/1341 | exploit vdb entry patch vendor advisory |