[NEWS] Lotus Domino Web Server File Retreival Vulnerability

From: support@securiteam.com
Date: 07/03/02


From: support@securiteam.com
To: list@securiteam.com
Date: Wed,  3 Jul 2002 08:01:20 +0200 (CEST)

The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

When was the last time you checked your server's security?
How about a monthly report?
http://www.AutomatedScanning.com - Know that you're safe.
- - - - - - - - -

  Lotus Domino Web Server File Retreival Vulnerability
------------------------------------------------------------------------

SUMMARY

Lotus Domino Web Server allows downloading of files in the web root
directory (rather than referring to the ECLs within the database or the
permissions on the file itself). This does not work on the standard web
scripts included in Domino such as admin4.nsf, names.nsf, domcfg.nsf, etc.
However, if there are other files or custom-made .nsf databases in the
server's web root directory, they may be downloaded by appending a "?" at
the end of the file name.

DETAILS

Vulnerable systems:
 * Lotus Domino R4 (version 4.x)

Immune systems:
 * Lotus Domino R5 (version 5.x)

Example:
Submitting the following URL:
http://dominoserver/nameoffile.ext?
Will retrieve instead of execute the file "nameoffile.ext".

Vendor response:
Lotus was notified about the issue. They noted that this issue had never
been reported and suggested a workaround that appears to correct the
issue.

Workaround:
Lotus suggested that you create a separate directory for the web site
files (do not put them in the web root created during installation). In
addition, the permissions on these files should be appropriately applied.

ADDITIONAL INFORMATION

The information has been provided by <mailto:packetsmack@digisec.org>
Andrew T.

========================================

This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.