Page 1 of 1

zoneminder frontdoor exploit found

Posted: Mon Jan 17, 2005 2:56 am
by reza
I've managed to find a security hole that will give you admin access in zoneminder without a need for a password. I've emailed the zoneminder user and gave him the details, and hope the fix gets out in the next release. I'm hessitant to give any details publicly till a patch is made to fix the hole. I'm posting here in case there is soneone else I should email. I couldn't find the author's email address on the website.

Reza

Posted: Mon Jan 17, 2005 3:34 am
by cordel
Thank you reza,
I'll email Phil and make sure he gets the info. I'll PM you with an email address to send the information. the next release is scheduled to come out in a day or two.
Cordel

Posted: Mon Jan 17, 2005 1:18 pm
by cordel
Info Forwarded
Thankyou,
Cordel

Posted: Tue Jan 18, 2005 12:00 am
by zoneminder
This problem has now been addressed.

Thanks for letting me kow.

Phil