R E L A T E D   C O N T E N T
ADVERTISEMENT

Security threat to Domino

Fears voiced that Domino Server 4.6 is vulnerable to hackers.

newmedia newmedia, Network IT Week 01 Sep 1999
ADVERTISEMENT

Lotus Notes Domino Server 4.6 users are leaving themselves wide open to denial of service attacks, according to security firm ISS.

ISS issued an advisory notice last week, saying that an overflow problem in Notes LDAP (NLDAP) Service could allow even inexperienced crackers - with off the shelf software - to crash servers, so bringing email and other Domino services to a standstill.

Hackers could sever vital communications links with ease, said Kevin Black, ISS sales director.

His advice to anyone using 4.6 was to immediately upgrade to version 4.6.6 or 5.0, which does not contain the security flaw. "The response we have had to this notice shows there is a considerable user base still using 4.6, which is worried about this problem," he said.

But Michael Chapman Pincher, head of operations at the User Group, an association for groupware professionals, said Lotus had a good security history and the ISS notice was one of the first warnings he had seen for Domino.

He argued that the LDAP problem would not affect many companies as most had already gone through the relatively simple process of upgrading their Domino servers. "Most hackers attack corporates because they make a better story, but large companies are generally the first to upgrade," he said.

According to ISS, the overflow is related to the way NLDAP handles the ldap_search request. By sending a large amount of data to the parameter in the request, an attacker could stop all Domino services on the affected machine.

www.lotus.com

www.iss.net.

See also:

Lotus Notes' security has come under fire from experts who this week demonstrated how email accounts could easily be broken into.  02 Aug 2000

All Hacking

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Computer People
SQL Server 2008 Developer – Staffordshire – Market Rate – 3 - 6 month initial role Computer People have an exciting opportunity for a SQL Server 2008 Developer within an Large organisation based in Staffordshire. ... more >
| Aston Carter
JAVA J2SE DEVELOPER – CREDIT DERIVATIVES amp; Credit Derivatives (CDS, CDO, CDX, IRD, IRS), Exotics and Structured Hybrid products. Technical skills include: Server side Java, SQL, Sybase, SOAP, WEB SERVICE and OOA/D. Nice to have ... more >
| Aston Carter
JAVA J2SE DEVELOPER – CREDIT DERIVATIVES amp; Credit Derivatives (CDS, CDO, CDX, IRD, IRS), Exotics and Structured Hybrid products. Technical skills include: Server side Java, SQL, Sybase, SOAP, WEB SERVICE and OOA/D. Nice to have ... more >
| Aston Carter
Java, C++, SQL Analyst Developer – Interest Rate Risk Java, C++, SQL, Analyst Developer, interest rate, risk, credit risk, market risk, perl, scripting • At least 2-5 years experience developing in C++ and Java • ... more >
More job opportunities