The Curious Case of the Password Database
ID: c61dfd8d-742e-516b-99a3-1050a055fd9b
STIX ID: report--c61dfd8d-742e-516b-99a3-1050a055fd9b
Feed Name: TrustedSec blog
Threat Score
TrustedSec analyzed ManageEngine Password Manager Pro after RCE vulnerabilities and demonstrated that an attacker with server access can recover the encrypted database password, extract the PMP key and the encrypted master key from the database, and decrypt stored user credentials; the report includes reproduction steps, SQL queries, decryption functions, and a released decryption script (Zoinks) to automate recovery.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
