webadmin.ntf exploit

From: Jeff Jackson (gbjwoa@yahoo.com)
Date: 02/13/02


Date: 13 Feb 2002 16:49:03 -0000
From: Jeff Jackson <gbjwoa@yahoo.com>
To: pen-test@securityfocus.com


('binary' encoding is not supported, stored as-is)

Im working on a penetration test for a small food
company in the midwest and I have been able to gain
access to the webadmin.ntf template on a domino
web server using the +++250+++ exploit. I have
seen several people mention that one can use this
template to view files located on the web server's file
system, but I haven't been able to find any details on
how this can be done. Does anyone have any insight
on how I can exploit this vulnerability to gain access
to the local file system? Thanks in advance.

- JJ

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/



Relevant Pages

  • Re: (citrix testing)
    ... For more information on SecurityFocus' SIA service which ... >- This list is provided by the SecurityFocus Security Intelligence Alert ... > automatically alerts you to the latest security vulnerabilities please ...
    (Pen-Test)
  • Re: Buffer Overflow Help
    ... >>> This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ... >>> automatically alerts you to the latest security vulnerabilities please ...
    (Pen-Test)
  • Re: IIS HTR Exploit ?
    ... > This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ... This list is provided by the SecurityFocus Security Intelligence Alert ... automatically alerts you to the latest security vulnerabilities please see: ...
    (Pen-Test)
  • Re: Need Novell vuln. scanner ASAP!
    ... > This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ... > automatically alerts you to the latest security vulnerabilities please see: ...
    (Pen-Test)
  • Re: faster scans? (nmap)
    ... one host using nmap for syn scans in burst mode with the ... >>>This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)