|
|||||||||||
|
Re: Lotus Notes
From: David Barnett <dbarn064(at)earthlink.net>
Date: Thu Nov 28 2002 - 08:50:29 EST -----BEGIN PGP SIGNED MESSAGE-----
Well I must concur with Chad as Notes default installs are wide open. Rarely when doing Pen tests have I found a correctly secured Notes/Domino server. Permissions are rarely correct for databases. While I am sure NexPose has done a fine job with their Vuln scanner, I have tried <unbiased commercial plug> AppDetective works really well for Lotus and Domino scans!! You can also use N-Stealth or any of your favorite web scanners and add the following files: /852566C90012664F
At 01:28 AM 11/27/2002 -0500, svetsanj@hotmail.com wrote: >We are doing a penetration testing for a client who has lotus notes. We >were able to access the catalog.nsf file from the web and other admin >pages such as the user list page, connections page database page etc. > >Question is, is this just a low level threat or can a hacker use this >info to hack further. Also clicking on some of the admin pages brings up >a default page which says click here to access page. On a notes client >its possible to click that page put not through http. Is there a >workaround url that bypasses that page? > > SKP > > > > > >---------------------------------------------------------------------------- >This list is provided by the SecurityFocus Security Intelligence Alert (SIA) >Service. For more information on SecurityFocus' SIA service which >automatically alerts you to the latest security vulnerabilities please see: > https://alerts.securityfocus.com/ -----BEGIN PGP SIGNATURE-----
This list is provided by the SecurityFocus Security Intelligence Alert (SIA) Service. For more information on SecurityFocus' SIA service which automatically alerts you to the latest security vulnerabilities please see: https://alerts.securityfocus.com/ Received on Thu Nov 28 13:08:46 2002 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:02:31 EDT |
||||||||||
|
|||||||||||