Vulnerability Development mailing list archives

Re: Lotus Domino 5.0.5 Web Server vulnerability - reading files outside the web root


From: Stefan Schmidt <sschmidt () INTRAWARE DE>
Date: Tue, 9 Jan 2001 16:29:22 +0100

You can temporarily fix the problem by creating a file protection. Protect
/.nsf/../ and set Default to no access. Also protect .ns4 and .box
The file protection will give You a login-prompt.

Stefan Schmidt
Manager IT
IntraWare AG
Brueckenmuehle 93 | D-36100 Petersberg
Phone +49 (0) 661/96 42-162 / Fax +49 (0) 661 - 96 42 99-162
Mobile +49 (0) 170/91 222 92
sschmidt () intraware de
http://www.intraware.de


Current thread: