[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Full-disclosure] Sonicwall license servers down .. all customers affected



> https://licensemanager.sonicwall.com/newui/admin/admin.jsp
>
> thats hilarious - it MUST be a kind of honeypot :P
>   

I think they threw up a new licensemanager server without reviewing the 
config .. it allows directory enumeration on a lot of pages (including 
the root).

This one is interesting :

https://licensemanager.sonicwall.com/js/ClientValidationMethods.js

Seems remote debug is on as well :

https://licensemanager.sonicwall.com/mf/fwregister_done.jsp

Cheers,

Michael Holstein CISSP GCIA
Cleveland State University

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/