Advertisement
Promo

Security threats Toolkit

Flaw found in Nortel's VPN client

Dan Ilet ZDNet.co.uk

Published: 22 Mar 2005 17:55 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Networks company Nortel is returning to the drawing board today after a security researcher claimed to have found a vulnerability in its virtual private network (VPN) software.

Security experts at NTA Monitor say that version 5.01 of Nortel's Contivity VPN client for Windows is flawed because it gives users the option of saving their VPN username and password on the computer from which they access the VPN. A hacker who gained access to the machine could find this information and then log onto the corporate network. Although the software stores the password in an encrypted format in the registry, it also stores an unencrypted copy in other places on the hard drive, NTA Monitor said.

"In my definition, I'd say this is a vulnerability," said Roy Hills, technical director for NTA Monitor. "If someone gets these details, it's a big problem, but it's a lot of effort, so let's not go overboard on this."

Nortel has acknowledged that it is unwise for users to save VPN passwords in this way, even though its software gives people this option.

"If you save your password in a VPN client, that is insecure," said a Nortel spokesman. "There is the option to save the password, but someone has to have access to your PC. It's something we plan to resolve. We don’t believe this to be a major problem."

Hills's team of researchers discovered the problem in October and passed full details over to Nortel four weeks ago. Hills said that Nortel failed to respond to warnings that it could have a problem and only contacted NTA Monitor today after being contacted by ZDNet UK.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
72 out of 165 people found this useful


Full Talkback thread

1 comment

  1. How is this "returning to the drawing board"??? I... Anonymous

Company/Topic Alerts

Create a new alert from the list below:




Video icon

Video

Sentry Posts Blog

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment

Authentication risks all too human

Risks to successful online banking identification and authentication using smartcards involve a mixture of human and technological factors, according to the European Network and Information... More

1 comment

Opera censors Chinese content

Opera has updated the Chinese version of its mobile browser to stop users accessing restricted content. Opera Mini was updated on Friday from an international to a Chinese version,... More

2 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters