[NEWS] Lotus Domino Web Server File Retreival Vulnerability

From: support@securiteam.com
Date: 07/03/02

From: support@securiteam.com
To: list@securiteam.com
Date: Wed,  3 Jul 2002 08:01:20 +0200 (CEST)

The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

When was the last time you checked your server's security?
How about a monthly report?
http://www.AutomatedScanning.com - Know that you're safe.
- - - - - - - - -

  Lotus Domino Web Server File Retreival Vulnerability


Lotus Domino Web Server allows downloading of files in the web root
directory (rather than referring to the ECLs within the database or the
permissions on the file itself). This does not work on the standard web
scripts included in Domino such as admin4.nsf, names.nsf, domcfg.nsf, etc.
However, if there are other files or custom-made .nsf databases in the
server's web root directory, they may be downloaded by appending a "?" at
the end of the file name.


Vulnerable systems:
 * Lotus Domino R4 (version 4.x)

Immune systems:
 * Lotus Domino R5 (version 5.x)

Submitting the following URL:
Will retrieve instead of execute the file "nameoffile.ext".

Vendor response:
Lotus was notified about the issue. They noted that this issue had never
been reported and suggested a workaround that appears to correct the

Lotus suggested that you create a separate directory for the web site
files (do not put them in the web root created during installation). In
addition, the permissions on these files should be appropriately applied.


The information has been provided by <mailto:packetsmack@digisec.org>
Andrew T.


This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com


The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.

Relevant Pages

  • Re: Drivel
    ... Word MVP web site http://word.mvps.org ... Microsoft Word 2003, ... I found an english thesaurus, ... Lotus software can do it. ...
  • Re: [PHP] Hide the real URL
    ... unintuitive to have things outside of your actual "web site." ... Let's say you want all of your client web directories under /var/www/vhosts. ... Create a dir for each client and set up each of your DocumentRoots as a dir inside of that one. ... This way all of your clients now have a directory above their web root that they can place into anything they want to keep private. ...
  • Reference web root from any directory?
    ... How do I reference the web root from any location within a web site? ... example, if I am several directories deep in a web site, say ...