Re: [FD] QNAP TS-469U shadow file world readable

2014-07-11 Thread David Kennedy
Looks like all of QNAP, TS-EC1679U-RP affected as well. On Fri, Jul 11, 2014 at 5:35 AM, Erik Auerswald wrote: > Hi, > > the same holds for a QNAP TS-459U. Besides, the shadow file on that box > contains MD5 hashes without salt. > > Cheers, > Erik > -- > La perfection est atteinte non quand il

Re: [FD] QNAP TS-469U shadow file world readable

2014-07-11 Thread Erik Auerswald
Hi, the same holds for a QNAP TS-459U. Besides, the shadow file on that box contains MD5 hashes without salt. Cheers, Erik -- La perfection est atteinte non quand il ne reste rien ajouter, mais quand il ne reste rien à enlever. -- Antoine de Saint-Exupéry On Fri, Jul 11,

Re: [FD] QNAP TS-469U shadow file world readable

2014-07-11 Thread Joerg Mertin
I can confirm that... QNap SS-839 [/etc] # pwd /etc [/etc] # ls -l shadow lrwxrwxrwx1 adminadminist 13 Aug 15 2013 shadow -> config/shadow [/etc] # ls -l config/shadow -rw-r--r--1 adminadminist 455 Jun 25 2013 config/shadow That is also the reason that my NAS has no

[FD] QNAP TS-469U shadow file world readable

2014-07-11 Thread Melchior Limacher
[cid:image001.png@01CF9CF6.9CE624D0] [cid:image002.png@01CF9CF6.9CE624D0] Cheers ___ Sent through the Full Disclosure mailing list http://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/