Penetration Testing mailing list archives
Lotus Notes
From: svetsanj () hotmail com
Date: Wed, 27 Nov 2002 01:28:07 -0500
We are doing a penetration testing for a client who has lotus notes. We were able to access the catalog.nsf file from the web and other admin pages such as the user list page, connections page database page etc. Question is, is this just a low level threat or can a hacker use this info to hack further. Also clicking on some of the admin pages brings up a default page which says click here to access page. On a notes client its possible to click that page put not through http. Is there a workaround url that bypasses that page? SKP ---------------------------------------------------------------------------- This list is provided by the SecurityFocus Security Intelligence Alert (SIA) Service. For more information on SecurityFocus' SIA service which automatically alerts you to the latest security vulnerabilities please see: https://alerts.securityfocus.com/
Current thread:
- Lotus Notes svetsanj (Nov 27)
- Re: Lotus Notes Chad Loder (Nov 27)
- Re: Lotus Notes M. Zeeshan Mustafa (Nov 27)
- Re: Lotus Notes David Barnett (Nov 28)
- <Possible follow-ups>
- Re: Lotus Notes Grant Torresan (Nov 29)