Remotely hacking Novell ?

From: Rainer Duffner (rainer@ultra-secure.de)
Date: Wed Jul 03 2002 - 12:50:00 EDT


Hi,

I have found some Novell-server during a pentest (in fact, the site is a
pretty much a complete Novell-Shop, minus things like Citrix).

Anyway, there's a webserver with some Novonyx (remember that ?) Sample-Files
and there's an LDAP-Server that exports what looks like part of the NDS
(minus passwords, but some email-addresses).

It also has 427/tcp and 524/tcp open (well, nmap says) - are there any tools
that can enumerate more information from the server through these ports - if
at all ?
I assume, these are Novell-specific ports.

Finally: does pandora only work locally ?

cheers,
Rainer

-- 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Rainer Duffner                   Munich
rainer@ultra-secure.de          Germany
http://www.i-duffner.de        Freising
========================================
    When shall we three meet again
  In thunder, lightning, or in rain?
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/


This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:53:23 EDT