Popular Remote Management Tool Allows Login Without Authentication

  • 1 May 2014
  • 1 reply
  • 596 views

Userlevel 7
Badge +54
A remote management tool used in some enterprises can be exploited by attackers to remotely connect to a host without needing any passwords, according to a Trustwave researcher.
 
Many organizations use the NetSupport software to remotely manage and connect to PCs and servers from a central location. These systems normally are set up with either Domain or local credentials, and shouldn't be accessible without the person logging in. However, if the system has NetSupport installed for remote desktop support, it most likely has the default configuration, which allows remote users to connect automatically without authentication, David Kirkpatrick, a principal consultant at Trustwave, wrote in a blog post. The software also leaks detailed information about the device, such as the hostname, version number, and the username.
 
Full Article

1 reply

Userlevel 7
Badge +56
That's a big security fail.

Reply