Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The mod_dialback module in Prosody before 0.9.9 does not properly generate random values for the secret token for server-to-server dialback authentication, which makes it easier for attackers to spoof servers via a brute force attack.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Prosody mod_dialback模块安全漏洞
Vulnerability Description
Prosody是一套使用Lua语言编写的Jabber/XMPP通信服务器软件。mod_dialback是其中的一个用于本地服务器之间通信的身份验证模块。 Prosody 0.9.9之前版本的mod_dialback模块中存在安全漏洞,该漏洞源于程序没有正确为server-to-server dialback身份验证的secret令牌生成随机数。攻击者可通过实施暴力破解攻击利用该漏洞欺骗服务器。
CVSS Information
N/A
Vulnerability Type
N/A