Re: lotus domino server 5.08 is very gabby

From: Darren Davison (dd@edefl.demon.co.uk)
Date: 09/20/01


From: Darren Davison <dd@edefl.demon.co.uk>
To: Frank.Boldewin@gmx.de, bugtraq@securityfocus.com
Subject: Re: lotus domino server 5.08 is very gabby
Date: Thu, 20 Sep 2001 12:17:54 +0000
Message-Id: <01092012175400.10830@bacall>


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Wednesday 19 September 2001 6:47 am, Frank.Boldewin@gmx.de wrote:
> maybe this is nothing new, but when i looked at some
> html raw headers after i surfed to a lotus domino 5.08 webserver,
> he tells me the following information :
>
> Lotus-Domino (Release 5.0.8 - June 18, 2001 on AIX)
>

put the following line in notes.ini to suppress this information..

DominoNoBanner=1

then restart the server. The default server installation does not include
this line in the file, and its default value is 0

> and further a request like this :
>
> GET //////////// HTTP/1.0
>
> gives me the internal ip-address, if the firewall or the router does NAT :
>
> HREF="http://10.65.59.30/

not sure about this one.

- --
~Darren
Public Key: http://www.edefl.demon.co.uk/pgp.html
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see http://www.gnupg.org

iD8DBQE7qd55NUhqHmdXZk4RAjUfAKDZvl+fZFjCNA8/eLlWDIxo3B4WhACffu4T
o3XNyihK5cVbdeCKj4iv+sA=
=fH6B
-----END PGP SIGNATURE-----



Relevant Pages

  • [NEWS] Lotus Domino DoS (Message Loop)
    ... Lotus Domino DoS (Message Loop) ... When a message is sent to a Lotus Domino server with an envelope similar ... There is a row of tabs on the top; ...
    (Securiteam)
  • Vulnerability discovered on Lotus Domino server "admin4.nsf"
    ... I'm doing an external blackbox PT on a mail server running Lotus ... The server OS is Windows 2000 and web server is Lotus Domino. ... this vulnerability and how to get a proper sense of it. ... vulnerability management needs. ...
    (Pen-Test)
  • [NT] Lotus Domino Physical Path Revealed
    ... Due to problems handling Windows DOS devices, the Domino Server can be ... - Lotus Domino version 5.0.9a on Windows 2000 Server ... The vendor was contacted on 7 February, ...
    (Securiteam)
  • Denial of Service in Lotus Domino 5.08 and earlier HTTP Server
    ... Denial of Service in Lotus Domino 5.08 and earlier HTTP Server ... There exists a DOS in the current version of Lotus Domino 5.08 and earlier. ...
    (Bugtraq)
  • Lotus Domino DoS
    ... Some oddly formed mail envelopes can cause Lotus Domino to ... enter a mail routing loop and consume 100% CPU. ... where domain.com is not local to the server in question, ... the server attempts to bounce the message, ...
    (Bugtraq)