Penetration Testing mailing list archives

Re: [PEN-TEST] OT: Lotus Notes name service (was: penetrating trojan)


From: Michael Rowe <mrowe () MOJAIN COM>
Date: Tue, 5 Dec 2000 23:10:35 -0500

On 00/12/05 01:53 +0000, Simon Waters wrote:

Anyone know whether Lotus Notes usage of an seperate name service was a
clever design decision, or just a result of historical accident?

What do you mean by "seperate name service"? Notes uses the name
resolution of whatever protocol you are using.

Well, to be more precise, it will fall back to the protocol's name
resolution if it has no "local" information (e.g. in a "location" or
"connection" document, or from the "home" server if its address is
known).

As for an "historical accident"... an historical explaination, at
least, if not accident:

Before Release 4, the only server platform was OS/2, and due to the
"historical accident" of LANserver/LANManager, typical installations
used NetBIOS as the protocol. R3 (at least--I never had the pleasure
of meeting R2) also supported IPX/SPX, TCP/IP and AppleTalk. But in
each case, Notes would simply use the name resolution of which ever
protocol was being used.

Cheers,

--
Michael Rowe <mrowe () mojain com>

AIM - RoweMichaelA                    Prof - ACM, IEEE, Computer Soc.
Web - http://www.mojain.com/          Vice - Barley malt, brewed or
Key - http://mojain.com/keys/mrowe.asc       distilled (hold the ice)


Current thread: