Kwelwild Posted April 9, 2013 Report Posted April 9, 2013 Google AD Sync Tool - Exposure of Sensitive Information VulnerabilitySense of Security - Security Advisory - SOS-13-001Release Date. 03-Apr-2013Last Update. - Vendor Notification Date. 03-Sep-2012Product. Google Active Directory Sync (GADS) ToolPlatform. Windows, Linux, SolarisAffected versions. All versions up to 3.1.3Severity Rating. HighImpact. Exposure of sensitive informationAttack Vector. From local without authenticationSolution Status. Upgrade to version 3.1.6CVE reference. CVE - not yet assignedDetails.Due to a weakness in the way the Java encryption algorithm(PBEwithMD5andDES) has been implemented in the GADS tool allstored credentials can be decrypted into plain-text. Thisincludes all of the encrypted passwords stored in any end-userssaved XML configuration file, such as Active Directory accounts,SMTP, Proxy details, LDAP and OAuth tokens, etc.Proof of Concept.Using the following information from the XML and GADS tool todecrypt all encrypted passwords from any XML:1. The hard coded salt: SALT[] = { -87, -101, -56, 50, 86, 53, -29, 3 }2. The hard coded DES interation count: ITERATION_COUNT = 203. The Secret key derived from the uniqueID value in the XML: 6512630db9a74d90a5531f574b85f3984. The cipher-text from the XML: <encryptedAdminPassword>1edOUtamjNA=</encryptedAdminPassword>5. The algorithm: PBEwithMD5andDESThe decrypted value is: winning!Solution.Upgrade to version 3.1.6Discovered by.Nathaniel Carew from Sense of Security Labs.About us.Sense of Security is a leading provider of information security andrisk management solutions. Our team has expert skills in assessmentand assurance, strategy and architecture, and deployment through toongoing management. We are Australia's premier application penetrationtesting firm and trusted IT security advisor to many of the country'slargest organisations.Sense of Security Pty LtdLevel 8, 66 King StSydney NSW 2000AUSTRALIAT: +61 (0)2 9290 4444F: +61 (0)2 9290 4455W: http://www.senseofsecurity.com.au/consulting/penetration-testingE: info@senseofsecurity.com.auTwitter: @ITsecurityAUThe latest version of this advisory can be found at:http://www.senseofsecurity.com.au/advisories/SOS-13-001.pdfOther Sense of Security advisories can be found at:http://www.senseofsecurity.com.au/research/it-security-advisories.phpSursa: Google AD Sync Tool - Exposure of Sensitive Information Vulnerability Quote