Vulnerability Development mailing list archives
Re: Novell Netware Copy
From: beels () TECHNOLOGIST COM (Richard Beels)
Date: Fri, 24 Mar 2000 09:14:27 -0700
Well, let's see here.... 1. NetWare security doesn't protect local drives, it protects network drives. Have yet to see or even hear of a package that breaks/overrides file trustee assignments. 2. The right click-enabled Netware Copy option is a plain hook into the ShellExtension/MenuHandler. 3. If your "local program" allows access to the C: drive in this case, I would look there first for the oversight or flaw. 4. Who is the "Admins of security flaws"? At 23:03 3/23/2000, first Last was inspired to say:
Through exploration on a LAN, I have found either a bug or an oversight on Novell Netware that allows a local user read/write access to any file on drive C (maybe network drives). When clicking on the right button on any file under Windows explorer, the local security program (FoolProof) turns off all selections except for an option called "Netware Copy". If one selects Netware Copy, it asks for a destination and you can type ANY file on drive C and it will either create a new file or overwrite the old file. Under normal usage, drive C is write protected. They're using the latest version of Novell Netware (4 or 5) with an OS of Win95. Can someone test to see if Netware Copy is a flaw or an oversight. I'm also wondering what are the ethics here. If there's something this easy, is it wrong to Netware Copy anything I want? (i.e. move security program, install other apps) <--Yes, I did notify the Admins of security flaws through e-mail but they never responded ______________________________________________________ Get Your Private, Free Email at http://www.hotmail.com
Cheers!
Current thread:
- Re: Intel Corporation, Express 550F Switch unlimited password attempts] Dustin D. Trammell (Mar 20)
- Re: Intel Corporation, Express 550F Switch unlimited password attempts] Juan M. Courcoul (Mar 23)
- Novell Netware Copy first Last (Mar 23)
- local security workaround through IE Knud Erik Højgaard (Feb 24)
- Re: local security workaround through IE thegreencow (Mar 24)
- Re: local security workaround through IE Blue Boar (Mar 24)
- Re: local security workaround through IE Knud Erik Højgaard (Feb 25)
- local security workaround through IE Knud Erik Højgaard (Feb 24)
- Re: Novell Netware Copy Richard Beels (Mar 24)
- Ehmm..in reagards to the con\con-problem, and ftp-servers Odd Arne Beck (Mar 24)
- Re: Novell Netware Copy Bob Fiero (Mar 24)
- Re: Novell Netware Copy Bluefish (Mar 25)
- <Possible follow-ups>
- Re: Intel Corporation, Express 550F Switch unlimited password attempts] Dustin D. Trammell (Mar 24)