Browse > Home / Graphic Matters / Non-secure network

Thursday, March 11, 2010 | Subscribe via RSS

Non-secure network

May 3rd, 2008 Posted in Graphic Matters

Novell NetWare Administrator has been shared (as in network shares) and can be executed by any user, and it can access the central server for the 1800+ student accounts and the 230+ staff accounts. The following screenshots show things that any logged-on user can access. (Clearly, I’ve taken out a few things for anonymity and to prevent others from abusing this ability. I plan on reporting this to a Site Admin.)

NetWare Administrator screen

More after the jump.

User information

More information

Still more

Teachers

Teacher information

The one fortunate thing is that NetWare Administrator (the program itself) isn’t that insecure. Non-administrators can’t modify certain details, like password policies. Nor can someone modify another person’s password. However, the main screen (user information) isn’t protected in the same way, and the system essentially serves as a list of the 1750+ students’ first and last names, in addition to the teachers and staff.

I hope this is corrected soon.

Tags:

Comments are closed.