|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
Subject: Re: Samba 2.0.7 SWAT vulnerabilities
From: Ryan Gray (ryan
SNIPER.ORG)Date: Wed Nov 01 2000 - 19:47:01 CST
- Next message: Linux Mandrake Security Team: "MDKSA-2000:065 - Linux-Mandrake not affected by dump"
- Previous message: Thomas Dullien: "Re: [VULN-DEV] Future of buffer overflows ?"
- In reply to: Richard Trott: "Re: Samba 2.0.7 SWAT vulnerabilities"
- Next in thread: Patrik Sternudd: "Re: Samba 2.0.7 SWAT vulnerabilities"
- Reply: Ryan Gray: "Re: Samba 2.0.7 SWAT vulnerabilities"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
CheckPoint Firewall-1 (at least up to version 4.0) has similar behavior.
Firewall-1 uses port 259 for client authentication.
If a valid username and invalid password is used:
User: validuser
FireWall-1 password: ******
Access denied by FireWall-1 authentication
User:
###################################
And if an invalid username is used:
User: invaliduser
User someuser not found
User:
###################################
I'm not sure about 4.1, but from the work that I've done with it, I'd
imagine that it behaves the same.
Regards,
Ryan Gray
Catalyst Solutions, Inc.
On Tue, 31 Oct 2000, Richard Trott wrote:
> I'm sure if everyone reported these problems to BugTraq, we could generate
> a very, very long list of products that have this same problem. I'd
> actually like to generate just such a list of products. Feel free to send
> example products (free, commercial, whatever) to me (and/or to Bugtraq;
> hey, it's moderated) and if I get enough, maybe I'll post a Web page.
>
> [CorporateTime for the Web also appears to do other
> not-so-security-conscious things like create a world writeable log
> directory (lexacal-private/log--and that private directory is created with
> world read and execute permissions, so it is not private at all).]
>
> Rich
>
- Next message: Linux Mandrake Security Team: "MDKSA-2000:065 - Linux-Mandrake not affected by dump"
- Previous message: Thomas Dullien: "Re: [VULN-DEV] Future of buffer overflows ?"
- In reply to: Richard Trott: "Re: Samba 2.0.7 SWAT vulnerabilities"
- Next in thread: Patrik Sternudd: "Re: Samba 2.0.7 SWAT vulnerabilities"
- Reply: Ryan Gray: "Re: Samba 2.0.7 SWAT vulnerabilities"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]