Collected research
VESTA Admin Takeover by exploiting bash $RANDOM limitations
Vesta Admin Takeover: Exploiting Reduced Seed Entropy in bash $RANDOM
Bash seeds its random variable by XORing microseconds and the process id into the timestamp without any bit shift, so only the low 20 bits vary and the seed lies within about a 12-day window of install time. Vesta control panel builds password-reset tokens from it, so an unauthenticated attacker can brute-force that range and predict the admin reset token.
Record
- Document
- Vesta Admin Takeover: Exploiting Reduced Seed Entropy in bash $RANDOM
- Researcher
- Adrian Tiron and @adrian__t
- Published by
- FORTBRIDGE
- Date
- Topic
- Other
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Adrian Tiron and @adrian__t, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .