Penetration Testing mailing list archives

Remotely hacking Novell ?


From: "Rainer Duffner" <rainer () ultra-secure de>
Date: Wed, 03 Jul 2002 16:50:00 +0000

Hi, I have found some Novell-server during a pentest (in fact, the site is a pretty much a complete Novell-Shop, minus things like Citrix). Anyway, there's a webserver with some Novonyx (remember that ?) Sample-Files and there's an LDAP-Server that exports what looks like part of the NDS (minus passwords, but some email-addresses). It also has 427/tcp and 524/tcp open (well, nmap says) - are there any tools that can enumerate more information from the server through these ports - if at all ? I assume, these are Novell-specific ports. Finally: does pandora only work locally ?

cheers,
Rainer
--
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Rainer Duffner                   Munich
rainer () ultra-secure de          Germany
http://www.i-duffner.de        Freising
========================================
   When shall we three meet again
 In thunder, lightning, or in rain?
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/


Current thread: