Penetration Testing mailing list archives

Novell volume changing?


From: "Charlie Liserne" <Chili () SexMagnet com>
Date: Mon, 07 Jan 2002 18:43:54 +0100

Dear all,

We are pen-testing a Novel 5.x webserver with the source page disclosure
problem (http://www.securityfocus.com/archive/1/246358).

We have been trying to get other volume indexing than SYS: We know that
there are more Volumes, and we know some of the file names of it, but we
aren't able to get to jump from SYS: to ANOTHER:

We tried something like:

http://server/lcgi/sewse.nlm?sys:/novonyx/suitespot/docs/sewse/viewcode.jse+
httplist+httplist/../../../../../ANOTHER:/file.ncf

and other variants, but it doesn't work. Please, do you know if it's
possible to disclosure another volume information too?

Regards,
Charlie.




----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/


Current thread: