HTTP: Lotus Domino Username Discovery

This signature detects attempts to exploit a known vulnerability in Lotus Domino Web Server 5.0.8. Attackers can directly request a user mail database to determine if the user account exists on the server; attackers can use this information create a more sophisticated attack or more intelligent brute forcing.

Extended Description

Successful exploitation of the vulnerability could allow a remote attacker to determine existing user names on a Lotus Domino Server. This may help them execute further attacks.

Short Name
HTTP:DOMINO:USERNAME-DISCOVERY
Severity
Warning
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
Discovery Domino Lotus Username
Release Date
04/22/2003
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Occasionally

Found a potential security threat?