Vissza a www.andrews.hu-ra

    [guru-merlin] [shalom@venera.com: IBM Lotus Notes multiple disclosures of password hashes]


    DATE: Mon, 22 Aug 2005 12:09:30 +0200
    2005 júniusában megjelent egy advisory, ami az IBM Lotus Domino webmail
    rendszer jelszó hash kiszivárgásáról szólt. A további vizsgálatok
    kimutatták, hogy a Lotus Notes kliens és a Domino LDAP is érintett.
    
    
    ----- Forwarded message from Shalom Carmel <shalom@venera.com> -----
    
    From: "Shalom Carmel" <shalom@venera.com>
    To: "bugtraq" <bugtraq@securityfocus.com>
    Subject: IBM Lotus Notes multiple disclosures of password hashes
    Date: Sat, 20 Aug 2005 04:54:01 +0300
    
    Summary
    ========
    
    A vulnerability describing password hashes disclosure in Domino
    
    webmail was published in July 2005.A further test revealed disclosed
    
    password hashes in the Lotus Notes client and in Domino LDAP.
    
    
    Details
    =======
    Lotus Notes client can be used to access the Notes Address Book (NAB).
    
    The Notes password digest is revealed on the Administration
    
    tab of an arbitrary person's entry.
    
    The "PasswordDigest" and "HTTPPassword" fields are revealed in the NAB
    entry's document properties.
    
    Domino LDAP also reveals the values of "PasswordDigest" and "HTTPPassword" .
    
    
    Vulnerable versions:
    ===================
    All versions
    
    
    Full details with examples can be found at
    http://www.venera.com/downloads/Lotus_password_disclosures.pdf
    
    
    Shalom Carmel
    -------------------
    www.venera.com - Exposing iSeries insecurity
    
    ----- End forwarded message -----
    
    
    

    Vissza a www.andrews.hu-ra