GHDB « Hackers For Charity



Google Search: Novell NetWare intext:"netware management portal version"

bungerScorpio rates this entry 6 out of 10.
Submitted: 2004-08-16 12:22:03
Added by: bungerScorpio
Hits: 1916
Score: 6

Netware servers ( v5 and up ) use a web-based management utility called Portal services, which can be used to view files on a volume, view server health statistics, etc. While you must log into the Portal Manager to view any of the data, it will accept blank passwords. So any Netware username defined in the server's NDS database w/o a password can authenticate.After the Google results are displayed, an attacker wil go to the company base web url and learn about employees, preferably their email addresses. Then bounce to the portal management login and try their username w/o a password.