Re: Script for find domino's users

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



31/01/2002 21:03:10, "Simon Delicata" <sdelicata@planer.co.uk> wrote :

>Two things can be done to avoid this :
>
>1 - Change the ACL on sensitive databases ( /mail/* , names.nsf ) to :
>      Anonymous - No access
>      [Default] - No access

In my opinion, a Domino webserver configured with these ACLs still allows enumeration of 
valid users.

If you try to GET a file named /mail/toto.nsf :
- toto doesn't exist => 404
- toto exists => redirection to the login page ("200 OK")

I'm not aware of any ACL configuration which forbid this behaviour.


Nicob




[Index of Archives]     [Linux Security]     [Netfilter]     [PHP]     [Yosemite News]     [Linux Kernel]

  Powered by Linux