bk99.de entertain the web since 1997

Novell’s NetWare full of security holes

Summary

At Black Hat 2002, Rain Forest Puppy presented numerous holes in NetWare 5.1 and 6.0 in the talk “Novell – The Forgotten OS”. Default installations could be crashed, NDS directory data read out and Perl scripts executed with system privileges. The recommendation was to remove the NetBasic, Perl and JSP handlers from the web servers until Novell delivered patches.

Ideas

  • Default installations opened up to eleven ports with web services.
  • Simple buffer overflows crashed the script handlers.
  • A neglected system attracts less scrutiny and stays vulnerable for longer.
  • Removing unused handlers was the quickest countermeasure.

Insights

  • Platforms that drop out of public focus accumulate undiscovered holes.
  • Every service installed alongside is attack surface, even if nobody uses it.

Facts

  • All three web servers available in NetWare were affected.
  • Novell announced that it would fix the problems at least partially by 5 August.

References

Critique

  • The report presents ways of attack but does not assess how many servers were reachable from the internet.

Recommendations

  • Disable web services and handlers that come with the default installation but are not needed.
  • Regularly check rarely noticed systems on the network for open services as well.

Read the original article

Search the Web Archive