20000410 CRYPTOAdmin 4.1 server with PalmPilot PT-1 token 1.04 PIN Extract ionmailing list
http://archives.neohapsis.com/archives/bugtraq/2000-04/0033.html CVE-2000-0275
CRYPTOCard CRYPTOAdmin 4.1 - Weak Encryption (1)
Record summary
CVE-2000-0275 has a selected CVSS score of 2.1; EIP currently links 2 catalogued exploits.
Description
CRYPTOCard CryptoAdmin for PalmOS uses weak encryption to store a user's PIN number, which allows an attacker with access to the .PDB file to generate valid PT-1 tokens after cracking the PIN.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBCRYPTOCard CRYPTOAdmin 4.1 - Weak Encryption (1)ExploitDB exploitby kingpinNot analyzed1 file
ExploitDBCRYPTOCard CRYPTOAdmin 4.1 - Weak Encryption (2)ExploitDB exploitby kingpinNot analyzed1 file
References
420000410 CRYPTOCard PalmToken PIN ExtractionVendor advisory
http://www.l0pht.com/advisories/cc-pinextract.txt 1097vdb entry
http://www.securityfocus.com/bid/1097 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2000-0275