Bugtraq mailing list archives

FileMaker Door


From: fuckme () FUCKYOU COM (LordShadow)
Date: Mon, 25 May 1998 20:12:36 -0400


     While doing some work from home I decided to see if I could open
the database in my office without pc-anywhere using Filemaker Pro...I
knew it ran over networks via tcp/ip,so I wanted to try over the
net...it worked,but I was awed that it allowed me to access the
databases without anytype of password or login prompt.....I thought
maybe I had set it up when I had installed FileMaker on my
system....so I installed it on my other workstation...and only set it
up to do tcp/ip and then dialed-up and logged right in again....no
pass..no login....dont know if anyone has seen this or posted this
before...but I havent been able to find anything out about it so
far...so I assume this is new.....anyway you need the IP of the target
machine which is gotten easily enough by scanning through domains for
services on port 5003 ( this seems to be its port ) and simply opening
your local copy of FM and then import thier data or whatever....Ive
sent what I found to the makers of FileMaker...maybe they know about
it...but since playing with this I have noticed a lot of machines
running this program and connected to the net.....



Current thread: