Web Hack List

Top 10 winner

Zimbra Email - Stealing Clear-Text Credentials via Memcache injection

Zimbra built Memcached lookup keys from usernames taken out of request URLs without escaping CRLF, so an unauthenticated attacker could inject arbitrary Memcached commands. Overwriting a user's IMAP route entry redirects their mail client to an attacker's server in cleartext, and injecting extra responses into the shared stream desynchronises it to reach unknown users.

Record

Researcher
Simon Scannell
Published by
Sonar
Date
Topic
Injection

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Simon Scannell, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .