Top 10 winner
Zimbra Email - Stealing Clear-Text Credentials via Memcache injection
Zimbra built Memcached lookup keys from usernames taken out of request URLs without escaping CRLF, so an unauthenticated attacker could inject arbitrary Memcached commands. Overwriting a user's IMAP route entry redirects their mail client to an attacker's server in cleartext, and injecting extra responses into the shared stream desynchronises it to reach unknown users.
Record
- Researcher
- Simon Scannell
- Published by
- Sonar
- Date
- Topic
- Injection
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Simon Scannell, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .