Keeweb-A web client for Keepass, CVE-2023-24055 Detection: Notorious Vulnerability in Keepass Potentially Exhibition Cleartext Passwords-Soc Prime

CVE-2023-24055 Detection: Notorious Vulnerability in Keepass Potentiallly Exhibition Cleartext Passwords

As Explained in the Research by Alex Hernandez and Detaied in a dedicated Sourceforge Thread, the Vulnerability in Question Might Allow An Attacker With Write access to the Xml Configuration File to Obtain the Cleartext Passwords by Adding An Export Trigger. The Poc Exploit for Cve-2023-24055, A Scanner for It, and A List of Trigger Examples Were Publicly posted on Alex Hernandez’s GitHub.

Keeweb – A web client for Keepass

If you use free Keepass software to manage your connections and other personal data, here Keeweb, A much prettier application to download in Desktop version (Windows, OSX, Linux) or to host yourself that is compatible with Keepass bases (KDBX).

keeweb

Keeweb does not require much in server since it consists only of an HTML page and JS. You can therefore put it everywhere, including on a dropbox (in application mode). And if you start from Keeweb to create your personal database, you can obviously open it in any original keepass.

Keeweb is of interest in mobility situations, when you cannot launch Keepass for reasons of security or limitations on the computer on which you are. A portable version on board a USB or full web key hosted on your server will be the solution and I reassure you, your KDBX file does not need to be stored online to be opened. You can access it from anywhere locally.

In addition, there is nothing sensitive in the Keeweb code … no external scripts, no third -party connections … etc. It’s 100% clean.

You can download Keeweb here in desktop version.

And do not forget that you must always remain vigilant about security, especially your passwords, so realize that with a tool like Keefarce your Keepass account has some potential vulnerabilities.

Discover an article at random ..

Start the discussion on Korben Community !

CVE-2023-24055 Detection: Notorious Vulnerability in Keepass Potentiallly Exhibition Cleartext Passwords

Stay Alert! Security Researchers have discovered a notorious vulnerability posing a serious threat to users of a popular password manager keepass. A Security FLAW, TRACKED AS CVE-2023-24055, Might Affect Keepass version 2.5x, potentialy Allowing Attackers to obtain Stored Passwords in Cleartext.

CVE-2023-24055 Detection

With proof-of-concept (POC) Available exploit, and in view that keepass is one of the most popular password managers globally, existing security glitch is a juicy target for attacks. To proactively detect malicious Activity Associated With CVE-2023-24055 Exploitation, Soc Prime’s Detection As Code Platforms Offers A Batch of Dedicated Sigma Rules .

Both Rules Above Detect Exploitation Patterns related to the keepass vulnerability in the spotlight and are based on the cve-2023-24055 poc exploit code . This code might be modified by adversaries to avoid detection and procedure with the attack while flying under the radar.

The detections are compatible with 22 siem, EDR, and xDR platforms and are Aligned with the MITRE ATT & CK® FRAMEWORK V12, Addressing the initial CREDENTIAL ACCESS AND EXFILTRATION TACTICS With Creddentials from Password Stores (T1555) and exfiltration over web service (T1567) Technical corresponding.

ALSO, to detect the malicious activity associated with potential cve-2023-24055 exploitation, soc prime team highly recommends apply the detection rules listed below:

Press the explore detections Button to Instantly Access All Dedicated Sigma Rules For Cve-2023-24055, accompanied by corresponding CTI LINKS, ATT & CK References, and Threat Hunting Ideas.

CVE-2023-24055 Analysis

Keepass is an extremely popular free open source Tool claimed to one of the Most Powerful and Secure Managers to Date. However, a novel vulnerability recently revealed to affect keepass might exhibits millions of uses to the risk of compromise.

As Explained in the Research by Alex Hernandez and Detaied in a dedicated Sourceforge Thread, the Vulnerability in Question Might Allow An Attacker With Write access to the Xml Configuration File to Obtain the Cleartext Passwords by Adding An Export Trigger. The Poc Exploit for Cve-2023-24055, A Scanner for It, and A List of Trigger Examples Were Publicly posted on Alex Hernandez’s GitHub.

Notebly, the Vendor States that the password database is not intended to be secure against an attack who has that that access to a local pc. Moreover, The List of Affuted Keepass versions is still disputed. For now, Keepass V2.5x is considered to be affected. Users are urged to upgrade to the latest 2.53 version to take potential compromises.

Boost Your Threat Detection Capabilitites and Accelerate Threat Hunting Velocity equipped with sigma, miter att & ck, and detection as code to always havey curated detection algorithms against any opponents ttp or any exploitable vulnerability at hand. Obtaining 800 rules for existing cves to proactively defnd against threats that matter most. Instantly reach 140+ sigma rules for free or get all receiving algorithms with on demand at https: // my.socprime.com/pricing/ .

Was this Helpful article?

Like and share it with your peers.

Join Soc Prime’s Detection As Code Platform To improve visability into threats Most being to your business. To help you get Started and Drive Immored Value, Book A Meeting Now With Soc Prime Experts.

Related Posts

CVE-2023-38146 Detection

Cert-i Warns of UAC-0057

Boost Your Cyber ​​Defense With Threat Detection Marketplace

The leading platform for detection as code and continuous security intelligence

Call with Soc Prime
Why Soc Prime?
  • Why Soc Prime?
  • Sigma
  • Center of Excellence for Microsoft Sentinel
  • Center of Excellence for Amazon Web Services
Pricing
Platform
Community
  • Community
  • Threat Bounty
  • Partner Programs for Universities
Tools
  • Acoder.Io
  • The Prime Hunt for:
Resources
Company
  • About US
  • Industry Recognition
  • Leadership
  • Careers
  • Privacy
  • SOC 2 Type II Compliance
  • Cookie Policy
  • Privacy Policy
  • SOC Prime Platform Terms of Service
  • Privacy FAQ

Soc Prime, Soc Prime Logo and Threat Detection Marketplace Are Registered Trademarks of Soc Prime, incl. All Other Trademarks Are the Property of Their respective Owners.

This Website USERS COOKIES COOKIES (Small Text Files that are stored by the Web Browser on the User’s Device) To Improve the User Experience While You Navigate Through The Website for the Statistical Analysis of Traffic and To Adapt the Content of the Website to your Individual Needs. It also lets us improvve your overall experience of the website. These cookies will only be stored in your browser with your consent.

However, if you would like to, you can opt-out of these cookies in your Browser Settings at Any Time. But opting out of some of these cookies may have a negative impact on your viewing experience. More information can be found in our cookie policy, and for a detailed list of the cookies we use, see our cookie settings.

Cookie Settings

Below is a detailed list of the cookies we used on site. We classify cookies in the following categories:

Strictly need Cookies

Cannot be switched off in our system. They are usually only set in actions to actions made by you that love to a request for services, such as setting your privacy prefeesions, logging in or filling in formms.
You can set your browser to block or alert you about these cookies, but some parts of the site will not then work. These cookies do not store any personally identifiable information.

Name Described
Phpressid Preserves User Selse State Across Page Requests. COOKIE Generated by Applications Based on the PHP LANGUAGE. This is a general purpose identify used to keep a variable session session. It is normally a random generated number, How it is used can be specific to the site, but a good example is mainaining a logged-in status for a user been pages.
SP_I Use to store information about authenticated user.
SP_R Use to store information about authenticated user.
spa Use to store information about authenticated user.

These allow Us to Count Visits and Traffic Sources so we can Measure and Improve the Performance of our site. They help us to know which pages are the most and least popular and see how visitors move the site.
All Information These Cookies Collect is aggregated and therefore anonymous. If you do not allow these cookies we will not know when you have visit our site, and will not be able to monitor its performance.

Name Described
tuuid Anonymous Data Related to the User’s Visits to the Website, Such as the Number of Visits, Average Time on the Website and What Pages have loaded.
tuuid_last_update Anonymous Data Related to the User’s Visits to the Website, Such as the Number of Visits, Average Time on the Website and What Pages have loaded.
UM Anonymous Data Related to the User’s Visits to the Website, Such as the Number of Visits, Average Time on the Website and What Pages have loaded.
umeh Anonymous Data Related to the User’s Visits to the Website, Such as the Number of Visits, Average Time on the Website and What Pages have loaded.
na_sc_x Use by the social sharing platform addthis to keep a record of parts of the site that has been visited in order to recommend other parts of the site.
Apid Anonymous Data Related to the User’s Visits to the Website.
Idsync Anonymous Data Related to the User’s Visits to the Website.
_cc_aud Anonymous Statistical Data Related To The User’s website Visits, Such as the Number of Visits, Average Time on the Website and What Pages have loaded. The purposes is to segment the website Users According to factors such as demographic and geographical rental, in order to enable media and marketing agencies to structure and understand their target groups to enable customized online advertising.
_cc_ccc Anonymous Statistical Data Related To The User’s website Visits, Such as the Number of Visits, Average Time on the Website and What Pages have loaded. The purposes is to segment the website Users According to factors such as demographic and geographical rental, in order to enable media and marketing agencies to structure and understand their target groups to enable customized online advertising.
_cc_DC Anonymous Statistical Data Related To The User’s website Visits, Such as the Number of Visits, Average Time on the Website and What Pages have loaded. The purposes is to segment the website Users According to factors such as demographic and geographical rental, in order to enable media and marketing agencies to structure and understand their target groups to enable customized online advertising.
_cc_id Anonymous Statistical Data Related To The User’s website Visits, Such as the Number of Visits, Average Time on the Website and What Pages have loaded. The purposes is to segment the website Users According to factors such as demographic and geographical rental, in order to enable media and marketing agencies to structure and understand their target groups to enable customized online advertising.
DPM Via A Unique Id that is used for semantic content analysis, the user’s navigation on the website is registered and linked to offline data from superys and similar registrations to display targeted ads.
ACS Anonymous Data Related to the User’s Visits to the Website, Such As the Number of Visits, Average Time on the Website and What Pages Have Been Loaded, with the purposes of displaying targeed ads.
clid Anonymous Data Related to the User’s Visits to the Website, Such As the Number of Visits, Average Time on the Website and What Pages Have Been Loaded, with the purposes of displaying targeed ads.
Krtbcookie_# Regisers A Unique Id that Identifies The User’s Device During Return Visits across Websites that use the same ad network. The id is used to allow targeted ads.
Pubmdcid Regisers A Unique Id that Identifies The User’s Device During Return Visits across Websites that use the same ad network. The id is used to allow targeted ads.
Pugt Regisers A Unique Id that Identifies The User’s Device During Return Visits across Websites that use the same ad network. The id is used to allow targeted ads.
ssi Regisers A Unique Id that identified a Returning User’s Device. The id is used for targeted ads.
_tmid Regisers A Unique Id that Identifies the User’s Device Upon Return Visits. The id is used to target ads in video clips.
WAM-SYNC Used by the Advertising Platform Weborama to Determine The Visitor’s Interests Based On Pages Visits, Content Clicked and Other Actions On the Website.
wui Used by the Advertising Platform Weborama to Determine The Visitor’s Interests Based On Pages Visits, Content Clicked and Other Actions On the Website.
Poster_w Used by the Advertising Platform Weborama to Determine The Visitor’s Interests Based On Pages Visits, Content Clicked and Other Actions On the Website.
B Anonymous Data Related To The User’s Website Visits Collects, Such As the Number of Visits, Average Time Spent On The Website and What Pages have been loaded. The Registered Data is used to categorize the Users’ Interest and Demographical Profiles with the purposes of Customising the Website Content Depending on the Visitor.
1p_jar These cookies are used to gather website statistics, and track conversion rats.
Apisid Google set a number of cookies on any page that included a google recaptcha. While we have no control over the cookies set by google, they appear to include a mixture of pieces of information to measure the number and behaviour of google recaptcha users.
Hsid Google set a number of cookies on any page that included a google recaptcha. While we have no control over the cookies set by google, they appear to include a mixture of pieces of information to measure the number and behaviour of google recaptcha users.
NEST Google set a number of cookies on any page that included a google recaptcha. While we have no control over the cookies set by google, they appear to include a mixture of pieces of information to measure the number and behaviour of google recaptcha users.
Sapisid Google set a number of cookies on any page that included a google recaptcha. While we have no control over the cookies set by google, they appear to include a mixture of pieces of information to measure the number and behaviour of google recaptcha users.
Sid Google set a number of cookies on any page that included a google recaptcha. While we have no control over the cookies set by google, they appear to include a mixture of pieces of information to measure the number and behaviour of google recaptcha users.
SIDCC Security Cookie to Protect Users Data from unauthivized access.
Ssid Google set a number of cookies on any page that included a google recaptcha. While we have no control over the cookies set by google, they appear to include a mixture of pieces of information to measure the number and behaviour of google recaptcha users.
__UTMX This cookie is Associated with Google Website Optimizer, A Tool Designed to help Owners Improve Their Wbesites. It is used to distinction between two varastions a webpage that might be shown to a visitor as part of an a/b split test. This helpps site owners to detemine that version of A page performs Better, and therefore helps to improve the Website.
__UTMXX This cookie is Associated with Google Website Optimizer, A Tool Designed to help Owners Improve Their Wbesites. It is used to distinction between two varastions a webpage that might be shown to a visitor as part of an a/b split test. This helpps site owners to detemine that version of A page performs Better, and therefore helps to improve the Website.

These cookies Enable The Website to Provid Enhanced Functionality and Personalization. They may be set by us or by third party providers whose services we have added to our pages.
If you do not ally these cookies then some or all of these services may not funuction properly.

Name Described
_Hjid Hotjar Cookie. This cookie is set the customer first lands on page with the hotjar script. It is used to persist the random user id, Unique to that site on the browser. This ensures that behavior in subsequent visits to the same site will be allocated to the same use.
_HJINCLUDEDINSAMPLE This cookie is Associated with Web Analytics Functionality and Services from Hot Jar, a Malta Based Company. It uniquely identifies a visitor during a single browser session and indicates they are included in an audience sample.
Intercom-ID- [XXX] This cookie is used by intercom as a session so that users can continue to chat asy move through the site.
Intercom-Salves- [XXX] Used to Keeping Track of Sessions and Remember Logins and Conversations.
demdex Via A Unique Id that is used for semantic content analysis, the user’s navigation on the website is registered and linked to offline data from superys and similar registrations to display targeted ads.
Cookient Stores The User’s Cookie Converse State For The Current Domain.
__cfduid Used by the Content Network, Cloudflare, To Identify Trusted Web Traffic.
ss These cookies Enable The Website to Provid Enhanced Functionality and Personalization . They may be set by us or by third party providers whose services we have added to our pages.
These services May include the Live Chat Facility, Contact US Form (S), The Product Quotation Forms and Submission Process, and the Email Newsletter Sign Up Functionality .

These cookies may be set through in site by our advertising partners. They may be used by those companies to build a profile of your interests and show you note adverts on other sites.
They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

Name Described
_Ga This Cookie Name is associated with Google Universal Analytics – Which is a significant update to google’s more commonly used analytics service. This cookie is used to distinction unique users by assiging a randomly generated number as a client identifier. It is included in each page. Regisers A Unique Id that is used to generate statistical data on How the Visitor USES The Website. Request in a site and use to calculate Visitor, Session and Campaign Data for the Sites Analytics Reports. By Default it is set to expire after 2 years, Although this is customizable by website Owners.
_Gat Used by Google Analytics to Throttle Request Rate. This Cookie Name is Associated With Google Universal Analytics, According to Documentation it is used to throttle the Request Rate – Limiting the Collection of Data on High Traffic sites. It expires after 10 minutes.
_gid This cookie name is associated with Google Universal Analytics. This appears to be a new cookie and as of spring 2017 no information is available from google. It appears to store and update a single value for each page visitd. Regisers A Unique Id that is used to generate statistical data on How the Visitor USES The Website.
Ide Used by Google Doubleclick to Register and Report the Website User’s actions After Viewing or Clicking One Of The Advertising’s Ads With the Purpose Of Measuring The Effectcy of An Ad and To Present Targeted Ads To The User.
R/Collect Used by Google Doubleclick to Register and Report the Website User’s actions After Viewing or Clicking One Of The Advertising’s Ads With the Purpose Of Measuring The Effectcy of An Ad and To Present Targeted Ads To The User.
test_cookie Used to check ifser’s browser supports cookies.
collect Used to send data to google analytics about the visitor’s device and behaviour. Tracks The Visitor Across Devices and Marketing Channels.
ADS/User-Lists/# These cookies may be set through in site by our advertising partners. They may be used by those companies to build a profile of your interests and show you note adverts on other sites.
vs Regisers anonymmed User Data, Such as Ip Address, Geographical Rental, Vised Websites, and What Ads the User has clicks, with the purposes of optimizing ad dispolate on the user’s movement on website that use the same ad network.
khaos Regisers anonymmed User Data, Such as Ip Address, Geographical Rental, Vised Websites, and What Ads the User has clicks, with the purposes of optimizing ad dispolate on the user’s movement on website that use the same ad network.
put_# Regisers anonymmed User Data, Such as Ip Address, Geographical Rental, Vised Websites, and What Ads the User has clicks, with the purposes of optimizing ad dispolate on the user’s movement on website that use the same ad network.
RPB Regisers anonymmed User Data, Such as Ip Address, Geographical Rental, Vised Websites, and What Ads the User has clicks, with the purposes of optimizing ad dispolate on the user’s movement on website that use the same ad network.
RPX Regisers anonymmed User Data, Such as Ip Address, Geographical Rental, Vised Websites, and What Ads the User has clicks, with the purposes of optimizing ad dispolate on the user’s movement on website that use the same ad network.
tap.php Regisers anonymmed User Data, Such as Ip Address, Geographical Rental, Vised Websites, and What Ads the User has clicks, with the purposes of optimizing ad dispolate on the user’s movement on website that use the same ad network.
Thanks! You've already liked this
No comments