Gadget Page
No Result
View All Result
  • Home
  • Apps
  • Gadget Info
  • Gaming
PRICING
SUBSCRIBE
  • Home
  • Apps
  • Gadget Info
  • Gaming
No Result
View All Result
Gadget Page
No Result
View All Result
Home Uncategorized

New Zimbra Email vulnerabilities may allow attackers to steal your login credentials

gadgetpage by gadgetpage
June 14, 2022
Reading Time: 5 mins read
0
New Zimbra Email vulnerabilities may allow attackers to steal your login credentials

RELATED POSTS

Puedes descargar Age of Empires III gratis y legalmente

Vanessa Kirby will play Sue Storm in Fantastic Four

Tower of Fantasy: Einjähriges Jubiläum und großes Update 3.1 angekündigt


Zimbra Email Suite reveals a new high-intensity vulnerability that, if used successfully, enables an unauthorized attacker to steal users’ ClearText passwords without any user interaction.

“With consequent access to victims’ mailboxes, attackers could increase their access to potentially targeted organizations and gain access to various internal services and steal highly sensitive information,” Sonarsource said. Says In a report shared with The Hacker News.

Track as CVE-2022-27924 (CVSS score: 7.5), the problem has been identified as “memecached poisoning with unverified requests”, which leads to a scenario where an adversary can inject malicious commands and siphoning sensitive information.

Cyber ​​security

This has been made possible by the application of poison IMAP Root cache entry on a memcached server that is used to track Zimbra users and forward their HTTP requests to appropriate backend services.

Given that Memcached incoming requests parse line-by-line, vulnerabilities allow an attacker to send a specially created lookup request to the server CRLF charactersThis allows the server to execute unwanted commands.

The error exists because “the character of the new line (r \ n) does not escape the trusted user input,” the researchers explained. “An error in this code ultimately allows attackers to steal cleartext certificates from users of targeted Zimbra instances.”

Equipped with this capability, the attacker could later cache the cache to overwrite an entry so that it forwarded all IMAP traffic to the attacker-controlled server, including the explicit text of the target user’s credentials.

Cyber ​​security

That said, the attack assumes that the adversary is already in possession of the victim’s email address in order to poison the cache entries and that they use an IMAP client to retrieve email messages from a mail server.

“Typically, an organization uses a pattern for email addresses for its members, such as {firstname} ৷ {lastname}@example.com,” the researchers said. “A list of email addresses can be found from OSINT sources such as LinkedIn.”

A threatening actor, however, can circumvent these restrictions using a technique called Response smugglingWhich includes “trafficking” unauthorized HTTP responses that misuse the CRLF injection error to forward IMAP traffic to a rogue server, causing users to steal certificates from them without their prior knowledge of their email addresses.

“The idea is that by constantly injecting more feedback than work items into memecached shared response streams, we can force random memecached lookups to use injected responses instead of the correct response,” the researchers explained. “It works because Zimbra did not verify the key to the memecached response when it received it.”

After the responsible release on March 11, 2022, there were patches to completely plug the security holes. Sent By Zimbar on May 10, 2022, in edition 8.8.15 P31.1 And 9.0.0 P24.1.

The findings come just months after cybersecurity firm Velocity launched an espionage campaign called Email Thief that armed zero-day vulnerabilities on email platforms to target European governments and media agencies in the wild.





Source link

Share this:

  • Twitter
  • Facebook
Tags: computer securitycyber attackcyber newscyber security newscyber security news todayCyber ​​Security UpdateCyber ​​updatedata breachhacker newshacking newshow to hackinformation securitynetwork securityransomware malwaresoftware vulnerabilities
ShareTweetPin
gadgetpage

gadgetpage

Related Posts

Puedes descargar Age of Empires III gratis y legalmente
Uncategorized

Puedes descargar Age of Empires III gratis y legalmente

August 4, 2023
Vanessa Kirby will play Sue Storm in Fantastic Four
Uncategorized

Vanessa Kirby will play Sue Storm in Fantastic Four

August 4, 2023
Tower of Fantasy: Einjähriges Jubiläum und großes Update 3.1 angekündigt
Uncategorized

Tower of Fantasy: Einjähriges Jubiläum und großes Update 3.1 angekündigt

August 3, 2023
OLED-Roadmap 2024: Monitorhersteller gibt Einblicke
Uncategorized

OLED-Roadmap 2024: Monitorhersteller gibt Einblicke

August 2, 2023
Samsung Galaxy SmartTag 2: Zertifizierung zeigt neues Design – Allround-PC.com
Uncategorized

Samsung Galaxy SmartTag 2: Zertifizierung zeigt neues Design – Allround-PC.com

August 2, 2023
Samsung Galaxy S23 FE: Neue Details zur Kamera
Uncategorized

Samsung Galaxy S23 FE: Neue Details zur Kamera

August 2, 2023
Next Post
Ask a director how to raise one – Social Media Explorer 7

Ask a director how to raise one - Social Media Explorer 7

Finding Skills in Wireless Space (Reader Forum)

Finding Skills in Wireless Space (Reader Forum)

Recommended Stories

Abandoned a number of projects, including smartwatches and consumer portal devices, to reduce meta costs.

Abandoned a number of projects, including smartwatches and consumer portal devices, to reduce meta costs.

June 10, 2022
What is doxing? Weaponizing personal information

What is doxing? Weaponizing personal information

August 31, 2020
Report: Nikon firmware for using CFexpress Type B cards with D5, D850 and D500 will arrive ‘before the end of 2020’

Report: Nikon firmware for using CFexpress Type B cards with D5, D850 and D500 will arrive ‘before the end of 2020’

October 11, 2020

Popular Stories

  • Xiaomi 13T is said to have a flagship camera on board – macro rubbish thrown away

    Xiaomi 13T is said to have a flagship camera on board – macro rubbish thrown away

    0 shares
    Share 0 Tweet 0
  • Gamescom 2023: Asus Republic of Gamers event with new products and contests

    0 shares
    Share 0 Tweet 0
  • Horizon Forbidden West, new major event: all accounts

    0 shares
    Share 0 Tweet 0
  • iPhone 12 mini Review | Trusted Reviews

    0 shares
    Share 0 Tweet 0
  • Sony Crystal LED Display System – LED Wall for Film Sets | CineD

    0 shares
    Share 0 Tweet 0
  • Home
  • Apps
  • Gadget Info
  • Gaming
Call us: +1 234 JEG THEME

© 2023 JNews - Premium WordPress news & magazine theme by Jegtheme.

No Result
View All Result
  • Home
  • Apps
  • Gadget Info
  • Gaming

© 2023 JNews - Premium WordPress news & magazine theme by Jegtheme.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?