Bugtraq mailing list archives
Re: Samba 2.0.7 SWAT vulnerabilities
From: Ryan Gray <ryan () SNIPER ORG>
Date: Wed, 1 Nov 2000 19:47:01 -0600
CheckPoint Firewall-1 (at least up to version 4.0) has similar behavior. Firewall-1 uses port 259 for client authentication. If a valid username and invalid password is used: User: validuser FireWall-1 password: ****** Access denied by FireWall-1 authentication User: ################################### And if an invalid username is used: User: invaliduser User someuser not found User: ################################### I'm not sure about 4.1, but from the work that I've done with it, I'd imagine that it behaves the same. Regards, Ryan Gray Catalyst Solutions, Inc. On Tue, 31 Oct 2000, Richard Trott wrote:
I'm sure if everyone reported these problems to BugTraq, we could generate a very, very long list of products that have this same problem. I'd actually like to generate just such a list of products. Feel free to send example products (free, commercial, whatever) to me (and/or to Bugtraq; hey, it's moderated) and if I get enough, maybe I'll post a Web page. [CorporateTime for the Web also appears to do other not-so-security-conscious things like create a world writeable log directory (lexacal-private/log--and that private directory is created with world read and execute permissions, so it is not private at all).] Rich
Current thread:
- Re: Samba 2.0.7 SWAT vulnerabilities Richard Trott (Nov 03)
- Re: Samba 2.0.7 SWAT vulnerabilities Gerald Carter (Nov 03)
- Re: Samba 2.0.7 SWAT vulnerabilities Ryan Gray (Nov 03)
- <Possible follow-ups>
- Re: Samba 2.0.7 SWAT vulnerabilities Patrik Sternudd (Nov 05)