Quantcast
Channel: Ignite Realtime: Message List
Viewing all articles
Browse latest Browse all 11593

Spark is using a publicly available key to encrypt passwords

$
0
0

Hi,

 

i had the same question since i have deployed Spark & OpenFire in our Company with the ability to logon via LDAP.

What i have discovered is that there is at least one security flaw because of some static/public known encryption key.

 

See this Links:

 

Spark/Encryptor.java at master · igniterealtime/Spark · GitHub ( privatestaticString secretKey ="ugfpV1dMC5jyJtqwVAfTpHkxqJ0+E0ae" )

 

1. Decrypting Spark Saved Passwords - Adam Caudill (worked for my Spark Version 2.6.3)

 

2. Recover Spark IM Stored Passwords with Metasploit - Pentest Geek - Penetration Testing - Infosec Professionals

 

I just stumbled onto this today, i think maybe i can circumvent this by compiling my own Spark binary (dunno, me is neewb).

 

Cya guys, btw spark rocks ! =)


Viewing all articles
Browse latest Browse all 11593

Trending Articles