Netware NDS默认特权漏洞

漏洞信息详情

Netware NDS默认特权漏洞

漏洞简介

Novell Netware NDS 5.99版本的安装为一个树提供带有Read使用权的未经认证的客户端,导致远程攻击者借助CX.EXE和NLIST.EXE访问敏感信息,例如:用户、群组以及可读对象。

漏洞公告

Remove CX.EXE and NLIST.EXE or disable public Read access from the root of your NDS tree.
Ensure all accounts have passwords, and that all assigned passwords are not easily guessed. Ensure Intruder Detection is turned on at the root of your NDS tree.

参考网址

来源: XF
名称: novell-nds(1364)
链接:http://xforce.iss.net/static/1364.php

来源: BID
名称: 484
链接:http://www.securityfocus.com/bid/484

来源: BUGTRAQ
名称: 19980918 NMRC Advisory – Default NDS Rights
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=90613355902262&w=2

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享