Using Domino5.0.7 webadmin.ntf to read files

From: Ilici Ramirez (ilici_ramirez@yahoo.com)
Date: 05/17/02


Date: Fri, 17 May 2002 06:11:33 -0700 (PDT)
From: Ilici Ramirez <ilici_ramirez@yahoo.com>
To: pen-test@securityfocus.com

Hello,

Supposing that 852566C90012664F is the ReplicaID of
webadmin.ntf,by using :
http://1.1.1.1:80/852566C90012664F/DBList?ReadForm
you can list databases on the server.

How can you read files from the web server using this?
What other things can you do with webadmin.ntf?

Regards,
Ilici

__________________________________________________
Do You Yahoo!?
LAUNCH - Your Yahoo! Music Experience
http://launch.yahoo.com

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/



Relevant Pages

  • Re: SQL
    ... | I am doing a pen test against a IIS 5 web server. ... This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • SQL
    ... I am doing a pen test against a IIS 5 web server. ... This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • RE: XSS LAB DEMO IDEAS
    ... I now have a "victim" web server set up that I can test XSS on, ... This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • Re: Using Domino5.0.7 webadmin.ntf to read files
    ... > you can list databases on the server. ... This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • WNServer Web Server
    ... I'm currently conducting a pen-test, and came across a WN 2.2.10 web server, ... This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)