Bugtraq mailing list archives

HP Secure Web Console


From: jrm () FREEDOM SWC COM (Jon Mitchell)
Date: Wed, 1 Dec 1999 09:05:40 -0600


The Secure Web Console is a device that looks (and acts) like a JetDirect
printserver.  It has one ethernet port and one serial port.  The idea
behind it is that you can connect your console cable from your HP9000
machine to this device and put it on the network.  This way you can
connect to your HP9000's via a web browser so remote access to the console
is easy.  Since this is actual console access you could potentially do
upgrades or reboots into single user mode safely from this device without
being onsite.

The problem with this device is the word Secure in the name.  This implies
that this device is providing secure access from the network.  The
information on this devices web site http://www.hp.com/go/webconsole
states that it currently uses MD5 user digest as the encryption scheme and
that future firmware will support SSL.  We have the latest firmware
installed at this time of A1.6 (A.01.06.001)

Upon first connecting we noticed that it would not support an SSL
connection as the documentation states.  Because even the first page you
access on this device is a Java applet, we assumed the best, that
encryption was somehow provided through that.  However we discovered that
it does not appear to be any sort of MD5 encryption scheme (although I'm
not an encryption expert), but in actuality what we've deemed Secret
Decoder Ring encryption.  The letters are one to one with another letter,
and even worse, in order as well.

Here's an example of two sets of letters:

You type:  abcd
Transmits: VUTS

You type:  ABCD
Transmits: vuts

Thanks to Joe Munson for helping debug this and coming up with the Secret
Decoder Ring reference (which reminded me of the Little Orphan Annie Ring,
that only says to drink more Ovaltine, in the Christmas Story).

--
Jon Mitchell
Systems Engineer, Subject Wills and Company
jrm () swc com



Current thread: