|
|||||||||||
|
Pen testing a CVS server
From: Bugsy <bugsy9999(at)yahoo.com>
Date: Sun May 18 2003 - 10:17:09 EDT
Im pentesting a server, which is running CVSpserver. I have gone through the CVS documentation and read other posts on securityfocus mailing lists. I am listing below what I have done so far, and would like to know if there is anything else that can be done with this. First, trying to login to the pserver with the command:
cvs -d :pserver:root@host.domain.com:/wrong/cvs/root
login
Enumerating usernames:
Checking passwords
Is there anything else that can be done. More specifically, is there some way to find out the version of the CVS server, without being able to login. Also, now that CVS server is that popular, shouldn't they build in basic security measures such as giving the same failure message whether the username, password or repository is wrong?
-Bugsy
Do you Yahoo!? The New Yahoo! Search - Faster. Easier. Bingo. http://search.yahoo.com
To get your FREE white paper visit us at: http://www.securityfocus.com/AirDefense-pen-test Received on Sun May 18 13:54:20 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:02:36 EDT |
||||||||||
|
|||||||||||