Skip to main content
 
developerWorks
AIX and UNIX
Information Mgmt
Lotus
New to Lotus
Products
How to buy
Downloads
Live demos
Technical library
Training
Support
Forums & community
Events
Rational
Tivoli
WebSphere
Java™ technology
Linux
Open source
SOA and Web services
Web development
XML
My developerWorks
About dW
Submit content
Feedback



developerWorks  >  Lotus  >  Forums & community  >  Notes/Domino 4 and 5 Forum

Notes/Domino 4 and 5 Forum

developerWorks

  

Sign in to participate PreviousPrevious NextNext

Foundstone and Domino
Alex L Nunez 1.Jun.07 10:06 AM a Web browser
Third-Party Tools -- Other 5.0.10 Windows 2000

While doing a vulnerability assessment and hardening of our servers, the Foundstone tool found this vulnerability on our Lotus Domino 5 server that we need to remediate:
----------------------------------------------------------
Name
Lotus Domino Webserver Administration Databases Disclosure
Risk
6
Intrusive
No
Description
An information disclosure vulnerability in Lotus Domino Server provides sensitive information regarding the target host.
Observation
Lotus Domino is an Application server designed to aid workgroups. It offers SMTP, POP3, IMAP, LDAP and Web services that allow users to interact with Lotus Notes databases.

Default installations of Lotus Domino include administrative database files which can be accessed anonymously. These files contain sensitive information regarding users, server configuration, access logs and operating system information.

The administrative database files are:

log.nsf,
domlog.nsf
catalog.nsf
mab.nsf
agentrunner.nsf
mtatbls.nsf
setup.nsf
mail.box
events4.nsf
admin4.nsf

An attacker could use GET html forms to access these database files and retrieve sensitive information regarding the target host.

Vulnerable Systems:

Lotus Domino 4.x, 5.x, 6.x


Recommendation
Currently no vendor-supplied patches are available for this issue.

Workaround:

Default installations of Lotus Domino may allow anonymous access to administrative database files. To fix this problem, verify the permissions for these databases and restrict access to only those accounts that need it.
----------------------------------------------------------

I've modified the ACLs and removed all Anonymous access capabilites from every database file and a recent scan still detects this as a vulnerability.

Looking for any tips and suggestions that will help me resolve this issue.

Thanks






  Document options
Print this pagePrint this page

 Search this forum

  Forum views and search
Date (threaded)
Date (flat)
With excerpt
Author
Category
Platform
Release
Advanced search

 Sign In or Register
Sign in
Forgot your password?
Forgot your user name?
Create new registration

 RSS feedsRSS
All forum posts RSS
All main topics RSS
More Lotus RSS feeds

 Resources
Forum use and etiquette
Native Notes Access
Web site Feedback

  Lotus Support
Lotus Support
Product support pages index
Search knowledge base (Technotes)
Search support downloads
Lotus Support RSS

 Wikis
IBM Composite Applications
IBM Mashup Center
IBM Connections
IBM Docs
IBM Forms
IBM Mobile Connect
IBM Sametime
IBM SmartCloud for Social Business
IBM Web Experience Factory
Lotus Domino
Lotus Domino Designer
Lotus Expeditor
Lotus Foundations
Lotus iNotes
Lotus Instructor Community Courseware
Lotus Notes
Lotus Notes & Domino Application Development
Lotus Notes Traveler
Lotus Protector
Lotus Quickr
Lotus Symphony
IBM Web Content Manager
WebSphere Portal

 Lotus Forums
Notes/Domino 9.0
Notes/Domino 8.5 + Traveler
Notes/Domino XPages development forum
Notes/Domino 8
Notes/Domino 6 and 7
Notes/Domino 4 and 5
IBM Connections
IBM Forms
IBM Mobile Connect
IBM Sametime
IBM SmartCloud Notes
IBM SmartCloud Meetings
IBM Web Content Manager
Lotus Domino Document Manager
Lotus e-learning
Lotus Enterprise Integration
Lotus Expeditor
Lotus Protector
Lotus Quickr
Lotus SmartSuite
Lotus Symphony
Lotus Symphony Developer Toolkit Support
Lotus Workflow