Full Disclosure mailing list archives

IBM developerWorks ncp (Nigel's Capacity Planning) 2.1 Remote Information Disclosure


From: BugsNotHugs <bugsnothugs () gmail com>
Date: Sat, 30 Jun 2012 16:22:23 -0600


http://www.ibm.com/developerworks/systems/articles/free_tools/index.html

Can visit ncp pages and get info without authentication!

http://target:8282/

gives version

http://target:8282/real/lsconf.html

detailed config info including:
System Model
Machine Serial Number
Processor Type
Number of Processors
Processor Clock Speed
CPU Type
Kernel Type
LAPR Info
Memory Size
Firmware Version
Console Login (if enabled or not)
Auto Restart status
Host Name
Gateway IP
Name Server
Domain Name
Volume Group Info

http://target:8282/real.html

Graphs for host
File System Use
CPU Utilisation (User+System)

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: