ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Flaw found in Nortel's VPN client

Dan Ilet ZDNet.co.uk

Published: 22 Mar 2005 17:55 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Networks company Nortel is returning to the drawing board today after a security researcher claimed to have found a vulnerability in its virtual private network (VPN) software.

Security experts at NTA Monitor say that version 5.01 of Nortel's Contivity VPN client for Windows is flawed because it gives users the option of saving their VPN username and password on the computer from which they access the VPN. A hacker who gained access to the machine could find this information and then log onto the corporate network. Although the software stores the password in an encrypted format in the registry, it also stores an unencrypted copy in other places on the hard drive, NTA Monitor said.

"In my definition, I'd say this is a vulnerability," said Roy Hills, technical director for NTA Monitor. "If someone gets these details, it's a big problem, but it's a lot of effort, so let's not go overboard on this."

Nortel has acknowledged that it is unwise for users to save VPN passwords in this way, even though its software gives people this option.

"If you save your password in a VPN client, that is insecure," said a Nortel spokesman. "There is the option to save the password, but someone has to have access to your PC. It's something we plan to resolve. We don’t believe this to be a major problem."

Hills's team of researchers discovered the problem in October and passed full details over to Nortel four weeks ago. Hills said that Nortel failed to respond to warnings that it could have a problem and only contacted NTA Monitor today after being contacted by ZDNet UK.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
61 out of 153 people found this useful


Full Talkback thread

1 comment

  1. How is this "returning to the drawing board"??? I... Anonymous

Company/Topic Alerts

Create a new alert from the list below:




Related Jobs

Change/Release Manager

Experience gained in support of production/business critical systems or services Receive and log incoming changes from clients and from external ...

Technical Support Analyst - Fife

You will monitor and manage the LAN and WAN infrastructures and desktop, install pc, printers and LAN equipment and provide first and second line ...

Head of Sales and Customer Relations

Develop major areas of focus and key selling messages/training for each Operational Group (OG)/industry vertical, working closely with OG leads and ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment