Remotely hacking Novell ?

From: Rainer Duffner (rainer@ultra-secure.de)
Date: Wed Jul 03 2002 - 09:50:00 PDT

  • Next message: H D Moore: "Re: Anyone recognises this ?"

    Hi, 
    
    I have found some Novell-server during a pentest (in fact, the site is a 
    pretty much a complete Novell-Shop, minus things like Citrix). 
    
    Anyway, there's a webserver with some Novonyx (remember that ?) Sample-Files 
    and there's an LDAP-Server that exports what looks like part of the NDS 
    (minus passwords, but some email-addresses). 
    
    It also has 427/tcp and 524/tcp open (well, nmap says) - are there any tools 
    that can enumerate more information from the server through these ports - if 
    at all ?
    I assume, these are Novell-specific ports. 
    
    Finally: does pandora only work locally ? 
    
    
    cheers,
    Rainer
    -- 
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Rainer Duffner                   Munich
    rainer@ultra-secure.de          Germany
    http://www.i-duffner.de        Freising
    ========================================
        When shall we three meet again
      In thunder, lightning, or in rain?
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
    Service. For more information on SecurityFocus' SIA service which
    automatically alerts you to the latest security vulnerabilities please see:
    https://alerts.securityfocus.com/
    



    This archive was generated by hypermail 2b30 : Wed Jul 03 2002 - 15:14:55 PDT