lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <4936979C.8050507@csuohio.edu> Date: Wed, 03 Dec 2008 09:28:44 -0500 From: Michael Holstein <michael.holstein@...ohio.edu> To: pUm <hijacka@...glemail.com> Cc: full-disclosure@...ts.grok.org.uk Subject: Re: Sonicwall license servers down .. all customers affected > https://licensemanager.sonicwall.com/newui/admin/admin.jsp > > thats hilarious - it MUST be a kind of honeypot :P > I think they threw up a new licensemanager server without reviewing the config .. it allows directory enumeration on a lot of pages (including the root). This one is interesting : https://licensemanager.sonicwall.com/js/ClientValidationMethods.js Seems remote debug is on as well : https://licensemanager.sonicwall.com/mf/fwregister_done.jsp Cheers, Michael Holstein CISSP GCIA Cleveland State University _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/