Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

January 25th, 2013, 15:24 GMT · By

BLOG

Security Experts Find Critical Backdoor in Barracuda Products

SHARE:

Adjust text size:


Security holes identified in Barracuda appliances Enlarge picture - Security holes identified in Barracuda appliances
Experts from SEC Consult Vulnerability Lab have identified a critical SSH backdoor which affects several Barracuda Networks products, including the Spam and Virus Firewall, Message Archiver, SSL VPN and Web Application Firewall.

According to researchers, cybercriminals could use several undocumented user accounts to gain root access to the appliances via SSH or via the terminal.

And there’s another issue. The SSH daemon which runs on the appliances is configured to allow connections only from whitelisted IP address ranges belonging to Barracuda and other unaffiliated entities.

The problem is that all these unaffiliated entities can access SSH on all the affected Barracuda appliances that are connected to the Internet.

Barracuda has taken some steps toward addressing the issues, but SEC Consult Vulnerability Lab says that they haven’t completely patched the security holes.

TELL US WHAT YOU THINK:

1,191 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


YouTube, Gmail, Google, Intel Turkmenistan Sites Defaced by Iranian Hackers

Expert Finds DOM-Based XSS Vulnerabilities on Kaspersky, Panda and AVG Sites

Microsoft Addresses XSS Vulnerability on Delish

Twitter Fixes Bug That Allowed Third-Party Apps to Access DMs Without Permission

Expert Claims to Have Identified Persistent XSS Flaw in Google’s Blogger Service

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM