Web Hack List

Collected research

VESTA Admin Takeover by exploiting bash $RANDOM limitations

Vesta Admin Takeover: Exploiting Reduced Seed Entropy in bash $RANDOM

Bash seeds its random variable by XORing microseconds and the process id into the timestamp without any bit shift, so only the low 20 bits vary and the seed lies within about a 12-day window of install time. Vesta control panel builds password-reset tokens from it, so an unauthenticated attacker can brute-force that range and predict the admin reset token.

Record

Document
Vesta Admin Takeover: Exploiting Reduced Seed Entropy in bash $RANDOM
Researcher
Adrian Tiron and @adrian__t
Published by
FORTBRIDGE
Date
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Adrian Tiron and @adrian__t, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .