OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Bugtraq archives for 2nd quarter (Apr-Jun) 1999: Re: Xylan OmniSwitch "features"

Re: Xylan OmniSwitch "features"

Jeff Murphy (jcmurphySMURFLAND.CIT.BUFFALO.EDU)
Thu, 1 Apr 1999 14:31:00 -0500

we tried this with Version 3.2.5.17 and we're able to get in.

-- inserted text --

> Number one: anyone can telnet to the switch and login, without knowing
> either user or passwod strings. No permission will be given to perform

If I understand this, I can hit CR and get in. Just hitting CR keeps
returning the login prompt, using any other character gets me to password,
but CR returns login failure.

> Number two: anyone can ftp to the switch, whitout knowing either user or
> password strings.

Nope, couldn't get in.

-- end inserted text --