Novell volume changing?

From: Charlie Liserne (Chili@SexMagnet.com)
Date: 01/07/02


Date: Mon, 07 Jan 2002 18:43:54 +0100
From: "Charlie Liserne" <Chili@SexMagnet.com>
To: pen-test@securityfocus.com

Dear all,

We are pen-testing a Novel 5.x webserver with the source page disclosure
problem (http://www.securityfocus.com/archive/1/246358).

We have been trying to get other volume indexing than SYS: We know that
there are more Volumes, and we know some of the file names of it, but we
aren't able to get to jump from SYS: to ANOTHER:

We tried something like:

http://server/lcgi/sewse.nlm?sys:/novonyx/suitespot/docs/sewse/viewcode.jse+
httplist+httplist/../../../../../ANOTHER:/file.ncf

and other variants, but it doesn't work. Please, do you know if it's
possible to disclosure another volume information too?

Regards,
Charlie.

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/



Relevant Pages

  • Article on Full Disclosure
    ... Subject: Article on Full Disclosure ... Hey folks, ... responsible disclosure. ... This list is provided by the SecurityFocus Security Intelligence Alert ...
    (Pen-Test)
  • Re: [Full-disclosure] Re: Call for new mailing lists @ SecurityFocus (X-POST)
    ... Do you mean symantec first checks every message which causes a delay? ... it's called delayed disclosure and it's called ... > information which used to be free before securityfocus 'went commercial' ... Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org ...
    (Full-Disclosure)