Re: Xylan OmniSwitch "features"

From: Shelton, Raymond A. (SheltonRat_private)
Date: Tue Apr 06 1999 - 11:23:28 PDT

  • Next message: Christopher P. Lindsey: "Re: More procmail"

    Okay, who _can_ duplicate this (serial connections to the console port don't
    count.)
    Regards,
    Raymond A. Shelton
    
    > -----Original Message-----
    > From:	Jeff Murphy [SMTP:jcmurphyat_private]
    > Sent:	Monday, April 05, 1999 12:18 PM
    > To:	BUGTRAQat_private
    > Subject:	Re: Xylan OmniSwitch "features"
    >
    > Jeff Murphy <jcmurphyat_private> writes:
    >
    > > we tried this with Version 3.2.5.17 and we're able to get in.
    >
    > 					  ^^^^
    > 		i meant to type "weren't" but left out a couple letters.
    > 		i.e. we can not get in using your instructions.
    >
    > >
    > > -- inserted text --
    > >
    > > > Number one: anyone can telnet to the switch and login, without knowing
    > > > either user or passwod strings. No permission will be given to perform
    > >
    > > If I understand this, I can hit CR and get in. Just hitting CR keeps
    > > returning the login prompt, using any other character gets me to
    > password,
    > > but CR returns login failure.
    > >
    > > > Number two: anyone can ftp to the switch, whitout knowing either user
    > or
    > > > password strings.
    > >
    > > Nope, couldn't get in.
    > >
    > > -- end inserted text --
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 14:41:43 PDT