Slashdot Mirror


Serious Password Reset Hole In Accellion Secure FTP

chicksdaddy writes "A security researcher who was looking for vulnerabilities in Facebook's platform instead stumbled on a much larger hole that could affect scores of firms who rely on a secure file transfer platform from Accellion. Writing on his blog on Monday, Israeli researcher Nir Goldshlager said he discovered the password reset vulnerability while analyzing a Accellion deployment that is used, internally, by Facebook employees. Goldshlager used public knowledge of the Accellion platform to access a hidden account creation page for the Facebook deployment and create a new Facebook/Accellion account linked to his e-mail address. After analyzing Accellion's password reset feature, he realized that — with that valid account — he could reset the password of any other Facebook/Accellion user with some cutting and pasting and a simple HTTP POST request, provided he knew the user's login e-mail address — effectively hijacking the account. Goldshlager said he informed Facebook and that the hole has been patched by Facebook and Accellion. However, other Accellion customers using private cloud deployments of the product could still be vulnerable."

15 of 27 comments (clear)

  1. Kudos to Facebook! by tekrat · · Score: 4, Insightful

    Facebook and the vendor patched the vulnerability... That's a first, usually the first response by any large corporation to being informed of a security hole is to either have the researcher arrested or sue the researcher. And then quietly hope no one else finds the hole...

    --
    If telephones are outlawed, then only outlaws will have telephones.
    1. Re:Kudos to Facebook! by dmomo · · Score: 3, Insightful

      Well, that's the case when the customers of the large corporation are the ones at risk. Here it is the large corporation who took action because it was them who were vulnerable. So, your old cynical view still stands!

    2. Re:Kudos to Facebook! by nthitz · · Score: 1

      Comeon... Some companies do indeed do that, but Facebook has a history completely opposite of what you describe (wrst to responsible disclosure) http://www.facebook.com/whitehat/bounty/

  2. Re:Hard truth by Anonymous Coward · · Score: 3, Funny

    Never trust a dolphin.

  3. "Private cloud deployment"? by sloth10k · · Score: 2

    You mean, like, I have their software installed on my server?

    1. Re:"Private cloud deployment"? by VortexCortex · · Score: 1

      Imagine a perfectly spherical volume of hot air...

  4. Famous last words? by godel_56 · · Score: 1

    Did you notice his final line in TFA

    "Soon i will publish OAuth bypass in Facebook.com, Cya Next time!,"

    Real or not? That would really stir things up.

    1. Re:Famous last words? by TheLink · · Score: 1

      I wouldn't be surprised if that's true.

      Especially when this bug existed: http://chingshiong.blogspot.co.uk/2013/01/facebook-bug-4-password-reset.html
      Which I think is more notable than a bug in Accellion (which I have never heard of, nor from what I've seen will ever want to use).

      --
  5. For real? by pclminion · · Score: 1

    Hey, I know -- let's pass the UID of the account which is being reset, in the URL which the attacker has control over. That's the ticket.

  6. Vulnerability patched 2 major version ago by Shurshacker · · Score: 1

    Accellion patched this vulnerability in version FTA_9_1_x (September?). They're currently on version FTA_9_3_1.

    1. Re:Vulnerability patched 2 major version ago by Shurshacker · · Score: 1

      This was all they found/patched with that security fix. From the Accellion engineer (Oh, and it was back in March)... "20-March-2012 FTA_9_1_166 Security Fix: The release fixes a vulnerability on the password update page."

  7. Who would have thought? by dbIII · · Score: 2

    Somebody managed to fuck up a version of FTP so badly it ended up as insecure as DropBox.

    1. Re:Who would have thought? by Shurshacker · · Score: 2

      Good thing it ain't FTP. ;)

  8. Re:Secure? As if! by egcagrac0 · · Score: 1

    We have a winner. The product is apparently grossly misnamed.

  9. Re:*shakes head* There's gotta be a better way... by OneAhead · · Score: 1

    I'm contemplating a tool that doesn't let us do that, but all that comes to mind is an animated paperclip saying "It looks like you're writing a security feature."