ID

VAR-200212-0116


CVE

CVE-2002-2049


TITLE

Fragroute/Dsniff/Fragrouter Configuration script Trojan vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-200212-452

DESCRIPTION

configure for Dsniff 2.3, fragroute 1.2, and fragrouter 1.6, when downloaded from monkey.org on May 17, 2002, has been modified to contain a backdoor, which allows remote attackers to access the system. The server hosting fragroute, fragrouter, and dsniff, www.monkey.org, was compromised recently. It has been reported that the intruder made modifications to the source code of fragroute, fragrouter and dsniff to include a backdoor. This backdoor allowed a user from the IP address 216.80.99.202 to remotely execute commands on the host that it was installed on. The source code is reported to have been corrupted on May 17, 2002. Downloads of the source from monkey.org during this time likely contain the trojan code. A confirmed MD5 sum of a contaminated archive is: 65edbfc51f8070517f14ceeb8f721075 If a fragroute install was based on an archive with this MD5 sum, it is likely that the backdoor code was executed. It is possible for other backdoored archives to have different MD5 sums. If it is believed that a trojan horse copy of fragroute has been installed, administrators should remove systems from the network and thoroughly inspect/clean the system. As of this writing (05-31-2002), the current version available from monkey.org has the following MD5 sum: 7e4de763fae35a50e871bdcd1ac8e23a It is believed that this version is clean. Caution should still be exercised when building and installing. Dsniff 2.3, fragroute 1.2, and fragrouter 1.6 configurations are vulnerable

Trust: 1.26

sources: NVD: CVE-2002-2049 // BID: 4898 // VULHUB: VHN-6432

AFFECTED PRODUCTS

vendor:dug songmodel:fragroutescope:eqversion:1.2

Trust: 1.6

vendor:dug songmodel:fragrouterscope:eqversion:1.6

Trust: 1.6

vendor:dug songmodel:dsniffscope:eqversion:2.3

Trust: 1.6

vendor:dugmodel:song fragrouterscope:eqversion:1.6

Trust: 0.3

vendor:dugmodel:song fragroutescope:eqversion:1.2

Trust: 0.3

vendor:dugmodel:song dsniffscope:eqversion:2.3

Trust: 0.3

sources: BID: 4898 // CNNVD: CNNVD-200212-452 // NVD: CVE-2002-2049

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2002-2049
value: HIGH

Trust: 1.0

CNNVD: CNNVD-200212-452
value: HIGH

Trust: 0.6

VULHUB: VHN-6432
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2002-2049
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-6432
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-6432 // CNNVD: CNNVD-200212-452 // NVD: CVE-2002-2049

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2002-2049

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200212-452

TYPE

Unknown

Trust: 0.9

sources: BID: 4898 // CNNVD: CNNVD-200212-452

EXTERNAL IDS

db:BIDid:4898

Trust: 2.0

db:NVDid:CVE-2002-2049

Trust: 1.7

db:CNNVDid:CNNVD-200212-452

Trust: 0.7

db:BUGTRAQid:20020531 TROJAN/BACKDOOR IN FRAGROUTE 1.2 SOURCE DISTRIBUTION

Trust: 0.6

db:XFid:9272

Trust: 0.6

db:VULHUBid:VHN-6432

Trust: 0.1

sources: VULHUB: VHN-6432 // BID: 4898 // CNNVD: CNNVD-200212-452 // NVD: CVE-2002-2049

REFERENCES

url:http://www.freebsd.org/cgi/query-pr.cgi?pr=38716

Trust: 2.0

url:http://www.securityfocus.com/bid/4898

Trust: 1.7

url:http://archives.neohapsis.com/archives/bugtraq/2002-05/0281.html

Trust: 1.7

url:http://www.iss.net/security_center/static/9272.php

Trust: 1.7

url:http://www.monkey.org/~dugsong/fragroute/

Trust: 0.3

sources: VULHUB: VHN-6432 // BID: 4898 // CNNVD: CNNVD-200212-452 // NVD: CVE-2002-2049

CREDITS

Vulnerability announced by Anders Nordby <anders@fix.no>.

Trust: 0.9

sources: BID: 4898 // CNNVD: CNNVD-200212-452

SOURCES

db:VULHUBid:VHN-6432
db:BIDid:4898
db:CNNVDid:CNNVD-200212-452
db:NVDid:CVE-2002-2049

LAST UPDATE DATE

2024-08-14T15:41:00.886000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-6432date:2008-09-05T00:00:00
db:BIDid:4898date:2002-05-31T00:00:00
db:CNNVDid:CNNVD-200212-452date:2005-10-20T00:00:00
db:NVDid:CVE-2002-2049date:2008-09-05T20:32:11.870

SOURCES RELEASE DATE

db:VULHUBid:VHN-6432date:2002-12-31T00:00:00
db:BIDid:4898date:2002-05-31T00:00:00
db:CNNVDid:CNNVD-200212-452date:2002-12-31T00:00:00
db:NVDid:CVE-2002-2049date:2002-12-31T05:00:00