[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Full-disclosure] Sonicwall license servers down .. all customers affected
- To: pUm <hijacka@xxxxxxxxxxxxxx>
- Subject: Re: [Full-disclosure] Sonicwall license servers down .. all customers affected
- From: Michael Holstein <michael.holstein@xxxxxxxxxxx>
- Date: Wed, 03 Dec 2008 09:28:44 -0500
> https://licensemanager.sonicwall.com/newui/admin/admin.jsp
>
> thats hilarious - it MUST be a kind of honeypot :P
>
I think they threw up a new licensemanager server without reviewing the
config .. it allows directory enumeration on a lot of pages (including
the root).
This one is interesting :
https://licensemanager.sonicwall.com/js/ClientValidationMethods.js
Seems remote debug is on as well :
https://licensemanager.sonicwall.com/mf/fwregister_done.jsp
Cheers,
Michael Holstein CISSP GCIA
Cleveland State University
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/