[19586] in bugtraq
Re: Vulnerability in Novell Netware
daemon@ATHENA.MIT.EDU (Derek Wilson)
Sun Mar 11 13:24:50 2001
Mime-Version: 1.0
Content-Type: multipart/signed; protocol="application/x-pkcs7-signature";
micalg=sha1; boundary="____TUSUJWVGSXKPCQSMRNGD____"
Message-ID: <20010309174616.AA87024CBA7@lists.securityfocus.com>
Date: Fri, 9 Mar 2001 11:49:00 -0500
Reply-To: WilsonD@GRANDCASINOS.COM
From: Derek Wilson <WilsonD@GRANDCASINOS.COM>
To: BUGTRAQ@SECURITYFOCUS.COM
--____TUSUJWVGSXKPCQSMRNGD____
Content-Type: text/plain; charset=iso-8859-1
Content-Transfer-Encoding: quoted-printable
Tested the Exploit on Netware 5.1 SP2 with the context and username set to =
the print server's context and username. I got an error logging in. No =
password was set for the print server (I don't think its possible). The =
printer was an NDPS printer. Does this only happen with "public access" =
printers, or was it a different service pack you tried it on?=20
Derek Wilson
wilsond@grandcasinos.com
PPE Mid-South Region
(V) 228.604.5106
(P) 228.516.3945
--____TUSUJWVGSXKPCQSMRNGD____
Content-Type: application/x-pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
CONTENT-DESCRIPTION: S/MIME Cryptographic Signature
MIIKdQYJKoZIhvcNAQcCoIIKZjCCCmICAQExCzAJBgUrDgMCGgUAMAsGCSqGSIb3DQEHAaCCCPow
ggKtMIICFqADAgECAgMDYAswDQYJKoZIhvcNAQEEBQAwgZQxCzAJBgNVBAYTAlpBMRUwEwYDVQQI
EwxXZXN0ZXJuIENhcGUxFDASBgNVBAcTC0R1cmJhbnZpbGxlMQ8wDQYDVQQKEwZUaGF3dGUxHTAb
BgNVBAsTFENlcnRpZmljYXRlIFNlcnZpY2VzMSgwJgYDVQQDEx9QZXJzb25hbCBGcmVlbWFpbCBS
U0EgMTk5OS45LjE2MB4XDTAwMTAwNTE5MTk1MVoXDTAxMDkwNTE5MTk1MVowSjEfMB0GA1UEAxMW
VGhhd3RlIEZyZWVtYWlsIE1lbWJlcjEnMCUGCSqGSIb3DQEJARYYd2lsc29uZEBncmFuZGNhc2lu
b3MuY29tMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCnqi0Rx0flAeDvtTMhqaT5H3/qpvOF
fAIv1jm/05sf2obukvMs6V22u4kqLD7+nlkw1V3zJI0ePmrkOmGL2UOzwIzc3CaYDSW+mvgNI4W8
ce2JOnJZPh8sg/MeQcHXAVvvJuZESVAsva6FrIMEsNqygeHeq67pKGjnyb01UEh9twIDAQABo1Yw
VDAjBgNVHREEHDAagRh3aWxzb25kQGdyYW5kY2FzaW5vcy5jb20wDAYDVR0TAQH/BAIwADAfBgNV
HSMEGDAWgBSIq/Fgg2ZV9ORYx0YdwGG9I9fDjDANBgkqhkiG9w0BAQQFAAOBgQCKULbUbU7bldha
G6Hy4VWzKrw6d+TC9BOKUyMHXyZOPGigTRqM4yvOVJPYVdsBFHzg9dpJfGc4n8O6M7j+YvN9V1QX
wRwDSeGWz+DFxSSRCuh2FIcM4cPzXO87eVe4akL/IWG4HpOnL7oH4SNEw3RrIb7D07qbY70bh7L8
L4eWFTCCAxQwggJ9oAMCAQICAQswDQYJKoZIhvcNAQEEBQAwgdExCzAJBgNVBAYTAlpBMRUwEwYD
VQQIEwxXZXN0ZXJuIENhcGUxEjAQBgNVBAcTCUNhcGUgVG93bjEaMBgGA1UEChMRVGhhd3RlIENv
bnN1bHRpbmcxKDAmBgNVBAsTH0NlcnRpZmljYXRpb24gU2VydmljZXMgRGl2aXNpb24xJDAiBgNV
BAMTG1RoYXd0ZSBQZXJzb25hbCBGcmVlbWFpbCBDQTErMCkGCSqGSIb3DQEJARYccGVyc29uYWwt
ZnJlZW1haWxAdGhhd3RlLmNvbTAeFw05OTA5MTYxNDAxNDBaFw0wMTA5MTUxNDAxNDBaMIGUMQsw
CQYDVQQGEwJaQTEVMBMGA1UECBMMV2VzdGVybiBDYXBlMRQwEgYDVQQHEwtEdXJiYW52aWxsZTEP
MA0GA1UEChMGVGhhd3RlMR0wGwYDVQQLExRDZXJ0aWZpY2F0ZSBTZXJ2aWNlczEoMCYGA1UEAxMf
UGVyc29uYWwgRnJlZW1haWwgUlNBIDE5OTkuOS4xNjCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkC
gYEAs2lal9TQFgt6tcVd6SGcI3LNEkxL937Px/vKciT0QlKsV5Xje2F6F4Tn/XI5OJS06u1lp5IG
Xr3gZfYZu5R5dkw+uWhwdYQc9BF0ALwFLE8JAxcxzPRB1HLGpl3iiESwiy7ETfHw1oU+bPOVlHiR
fkDpnNGNFVeOwnPlMN5G9U8CAwEAAaM3MDUwEgYDVR0TAQH/BAgwBgEB/wIBADAfBgNVHSMEGDAW
gBRyScJzNMZV9At2coF+d/SH58ayDjANBgkqhkiG9w0BAQQFAAOBgQBrxlnpMfrptuyxA9jfcnL+
kWBI6sZV3XvwZ47GYXDnbcKlN9idtxcoVgWL3Vx1b8aRkMZsZnET0BB8a5FvhuAhNi3B1+qyCa3P
LW3Gg1Kb+7v+nIed/LfpdJLkXJeu/H6syg1vcnpnLGtz9Yb5nfUAbvQdB86dnoJjKe+TCX5V3jCC
Ay0wggKWoAMCAQICAQAwDQYJKoZIhvcNAQEEBQAwgdExCzAJBgNVBAYTAlpBMRUwEwYDVQQIEwxX
ZXN0ZXJuIENhcGUxEjAQBgNVBAcTCUNhcGUgVG93bjEaMBgGA1UEChMRVGhhd3RlIENvbnN1bHRp
bmcxKDAmBgNVBAsTH0NlcnRpZmljYXRpb24gU2VydmljZXMgRGl2aXNpb24xJDAiBgNVBAMTG1Ro
YXd0ZSBQZXJzb25hbCBGcmVlbWFpbCBDQTErMCkGCSqGSIb3DQEJARYccGVyc29uYWwtZnJlZW1h
aWxAdGhhd3RlLmNvbTAeFw05NjAxMDEwMDAwMDBaFw0yMDEyMzEyMzU5NTlaMIHRMQswCQYDVQQG
EwJaQTEVMBMGA1UECBMMV2VzdGVybiBDYXBlMRIwEAYDVQQHEwlDYXBlIFRvd24xGjAYBgNVBAoT
EVRoYXd0ZSBDb25zdWx0aW5nMSgwJgYDVQQLEx9DZXJ0aWZpY2F0aW9uIFNlcnZpY2VzIERpdmlz
aW9uMSQwIgYDVQQDExtUaGF3dGUgUGVyc29uYWwgRnJlZW1haWwgQ0ExKzApBgkqhkiG9w0BCQEW
HHBlcnNvbmFsLWZyZWVtYWlsQHRoYXd0ZS5jb20wgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGB
ANRp19SwlGRbcelH2AxRtupykbCEXn0tDY97Et+FJXUodDpCLGMnn5V7S+9+GYcdhuqj3bnOlmQa
whRuRKx85o/oTQ9xH0A4pgCjh3j2+ZSGXq3qwF5269kUo11uenwMpUtVfwYZKX+emibVars4JAhq
mMex2qOYkf152+VaxBy5AgMBAAGjEzARMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQEEBQAD
gYEAx+ySfk749ZalZ2IqpPBNEWDQb41gWGGsJrtSNVwIzzD7qEqWih9iQiOMFw/0umScF6xHKd+d
mF7SbGBxXKKs3Hnj524ARx+1DSjoAp3kmv0T9KbZfLH43F8jJgmRgHPQFBveQ6mDJfLmnC8Vyv6m
q4oHdYsM3VGEa+T40c53ooExggFDMIIBPwIBATCBnDCBlDELMAkGA1UEBhMCWkExFTATBgNVBAgT
DFdlc3Rlcm4gQ2FwZTEUMBIGA1UEBxMLRHVyYmFudmlsbGUxDzANBgNVBAoTBlRoYXd0ZTEdMBsG
A1UECxMUQ2VydGlmaWNhdGUgU2VydmljZXMxKDAmBgNVBAMTH1BlcnNvbmFsIEZyZWVtYWlsIFJT
QSAxOTk5LjkuMTYCAwNgCzAJBgUrDgMCGgUAMA0GCSqGSIb3DQEBAQUABIGAp3mJciL4Ew4Cjw/t
8HuuWGCKF9BGSGHY1p0n2vqff3HL/gP1SgA6TRyCo44h1JmcCJsUQKJ/PWxx7uEPg4QF8XWdrMYy
kTt+f8KjmWnNczNkiazwGAkG73q4RkqSO+IeokxCgAimhKQdEvhxjurQUoUZRrfFOYUc85iik/ei
cg0=
--____TUSUJWVGSXKPCQSMRNGD____--