CRYPTOCard CRYPTOAdmin 4.1 - Weak Encryption (2)
Author: kingpin
type: local
platform: windows
port:
date_added: 2000-04-10
date_updated: 2012-07-15
verified: 1
codes: CVE-2000-0275;OSVDB-10054
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/1097/info
CRYPTOCard CRYPTOAdmin is a network authentication application for use with the Palm OS platform. CRYPTOAdmin generates a .pdb file which contains the username, PIN number, serial number, and key in encrypted or plaintext format. The PIN number can be retrieved due to the software's usage of a fixed 4-byte value in key generation. With access to the .pdb file and PIN number, a user is capable of duplicating the token onto another Palm device effectively gaining access to the network as the compromised user.
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/19839.zip