Decrypting Symantec BackupExec passwords
ID: c077871b-9634-5ec5-a23f-e320e320e749
STIX ID: report--c077871b-9634-5ec5-a23f-e320e320e749
Feed Name: SensePost Blog
Threat Score
The report describes that BackupExec stores encrypted service and AD account passwords (512-byte blobs) in its BEDB MS SQL backend and that an attacker can obtain these by compromising the database or obtaining the BEDB backup file (data/bedb.bak) from the installation directory; decrypted passwords can be recovered using bemsdk.dll and supplied C code, demonstrated against BackupExec 10.0.5484.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
