Novell NetWare NDS Domain Admin Null Password Vulnerability
BID:4012
Info
Novell NetWare NDS Domain Admin Null Password Vulnerability
| Bugtraq ID: | 4012 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 31 2002 12:00AM |
| Updated: | Jan 31 2002 12:00AM |
| Credit: | nobody <[email protected]> publicly disclosed this issue on January 31st, 2002. |
| Vulnerable: |
Novell Netware 5.1 Novell Netware 5.0 SP5 Novell Netware 5.0 |
| Not Vulnerable: | |
Discussion
Novell NetWare NDS Domain Admin Null Password Vulnerability
Novell NetWare is reportedly prone to an issue which may, under some circumstances, allow an unprivileged NDS user to access NT domain machines using a null password.
The attacker must possess a valid NDS account. The attacker must target a NDS_ADM account that is in the NDS tree and is checked as having "Domain Admin" rights over the NT domain, but must not exist in the NT domain. If these conditions are satisfied, then it is allegedly possible for the unprivileged NDS user to gain unauthorized access to machines in the NT Domain with the privileges of a Domain Admin.
This issue may be the result of a misconfiguration on the part of the user.
Novell NetWare is reportedly prone to an issue which may, under some circumstances, allow an unprivileged NDS user to access NT domain machines using a null password.
The attacker must possess a valid NDS account. The attacker must target a NDS_ADM account that is in the NDS tree and is checked as having "Domain Admin" rights over the NT domain, but must not exist in the NT domain. If these conditions are satisfied, then it is allegedly possible for the unprivileged NDS user to gain unauthorized access to machines in the NT Domain with the privileges of a Domain Admin.
This issue may be the result of a misconfiguration on the part of the user.
Exploit / POC
Novell NetWare NDS Domain Admin Null Password Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
Novell NetWare NDS Domain Admin Null Password Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Novell NetWare NDS Domain Admin Null Password Vulnerability
References:
References: