353 Lotus blogs updated hourly. Who will post next? Home | Downloads | Events | Jobs | Twitter | Bookmarks | Pods | Forum | Blogs | Search | myPL | About 
 
Latest 7 Posts
Making Sametime work on iOS
Wed, Feb 1st 2012 191
IBM Lotus Domino RPC Operation Denial of Service Vulnerability
Tue, Jan 3rd 2012 137
IBM Lotus Domino Remote Console Authentication Bypass Vulnerability
Thu, Dec 1st 2011 104
IBM Sametime client for iOS
Tue, Nov 22nd 2011 79
Advisory: Range header DoS vulnerability Apache HTTPD 1.3/2.x (CVE-2011-3192) -> IBM HTTP Server too!
Thu, Aug 25th 2011 92
Vulnerabilities in BlackBerry Enterprise Server components that process images could allow remote code execution
Fri, Aug 12th 2011 59
Extracomm releases a nice freebee: iPhone App for Lotus Notes/Domino Out of Office
Mon, Jul 25th 2011 93
Top 10
Making Sametime work on iOS
Wed, Feb 1st 2012 191
Notes 8.5.2 download part numbers
Tue, Aug 24th 2010 189
IBM Lotus Domino RPC Operation Denial of Service Vulnerability
Tue, Jan 3rd 2012 137
Security enhancements in iNotes 8.5.2 may require configuration changes in environments with reverse proxies
Fri, Jun 17th 2011 106
IBM Lotus Domino Remote Console Authentication Bypass Vulnerability
Thu, Dec 1st 2011 104
Extracomm releases a nice freebee: iPhone App for Lotus Notes/Domino Out of Office
Mon, Jul 25th 2011 93
Advisory: Range header DoS vulnerability Apache HTTPD 1.3/2.x (CVE-2011-3192) -> IBM HTTP Server too!
Thu, Aug 25th 2011 92
Fixing routing errors: "No route found to Domain from Server, Check Server, Connection and Domain documents in the Domino Directory."
Mon, Nov 29th 2010 90
IBM Sametime client for iOS
Tue, Nov 22nd 2011 79
IBM WebSphere Application Server JAX-RPC WS-Security/JAX-WS Runtime Security Bypass Vulnerability
Fri, Jun 17th 2011 77


Sorry, no records were found!

Recent Blog Posts
191


Making Sametime work on iOS
Wed, Feb 1st 2012 12:58a   Dennis van Remortel
*warning: high sarcasm levels* We wanted to use the Sametime iOS client for our iPad, so we installed Sametime 8.5.2 and applied IFR 1. Then we created PMR's, PMR's, PMR's and PMR's, and now I can inform you of the "well documented" steps you have to take after installing the software. Step 0: Get the latest version of the iOS app (or install updates). There are some mighty important fixes in there (part of which coming from my forementioned PMR's). Step 1: Creating a Proxy Serve [read] Keywords: domino ibm ldd lotus sametime database iphone server
137


IBM Lotus Domino RPC Operation Denial of Service Vulnerability
Tue, Jan 3rd 2012 12:31a   Dennis van Remortel
According to the IBM page about this: "If an attacker can monitor and record all communications between a Notes client and a Domino server then it is possible to crash the Domino server by modifying a specific packet, in a specific way, during a specific operation.", so a relatively low threat. Upgrade to 8.5.3 if you can, if not (because of the server changes in 8.5.3) upgrade to 8.5.2 FP4. Source: SecurityFocus IBM Lotus Domino RPC Operation Denial of Service Vulnerability [read] Keywords: domino ibm lotus notes notes client application network security server
104


IBM Lotus Domino Remote Console Authentication Bypass Vulnerability
Thu, Dec 1st 2011 12:34a   Dennis van Remortel
Via SecurityFocus: Bugtraq ID: 46985 Class: Unknown CVE: CVE-2011-1519 Remote: Yes Local: No Published: Mar 22 2011 12:00AM Updated: Dec 01 2011 06:36AM Credit: Patrik Karlsson [read] Keywords: domino ibm lotus archive server
79


IBM Sametime client for iOS
Tue, Nov 22nd 2011 12:38a   Dennis van Remortel
Finally, IBM has released the mobile client for Sametime. Note the specific version of the Proxy Server you'll need: 8.5.2 IFR 1. IBM Sametime Description *The IBM Sametime Mobile Client for iOS devices requires the Sametime 8.5.2 IFR 1 Proxy Server to be deployed in your infrastructure environment. Please contact your IT department to validate this is the case.* We are very excited to bring you the IBM Sametime Mobile Client for iOS! This gives you access to IBM's awar [read] Keywords: domino ibm sametime apple application desktop interface iphone mobile server unified communications wiki
92


Advisory: Range header DoS vulnerability Apache HTTPD 1.3/2.x (CVE-2011-3192) -> IBM HTTP Server too!
Thu, Aug 25th 2011 2:18a   Dennis van Remortel
Go read this, and apply the fixes. Your IBM HTTP server with the Websphere servers is just a rebranded Apache. Example: D:IBMbin>Apache.exe -v Server version: IBM_HTTP_Server/6.0.2.29 Apache/2.0.47 Excerpt below: Apache HTTPD Security ADVISORY ============================== Title: Range header DoS vulnerability Apache HTTPD 1.3/2.x CVE: CVE-2011-3192: Date: 20110824 1600Z Product: Apache HTTPD Web Server Versions: Apache 1.3 all versions, Apache 2 all versi [read] Keywords: domino ibm security server websphere
59


Vulnerabilities in BlackBerry Enterprise Server components that process images could allow remote code execution
Fri, Aug 12th 2011 12:39a   Dennis van Remortel
From the blackberry site. I've posted an excerpt below: Overview Vulnerabilities exist in components of the BlackBerry Enterprise Server that process PNG and TIFF images for rendering on the BlackBerry smartphone. The BlackBerry® Mobile Data System – Connection Service component processes images on web pages that the BlackBerry® Browser requests. The BlackBerry® Messaging Agent component processes images in email messages. Affected Software The issue affect [read] Keywords: agent domino ibm lotus blackberry email enterprise exchange exchange microsoft mobile server




93


Extracomm releases a nice freebee: iPhone App for Lotus Notes/Domino Out of Office
Mon, Jul 25th 2011 6:49a   Dennis van Remortel
My colleague found this on the appstore today, and it might look like a usefull thing for users forgetting their OOO. If you are using Lotus Traveler, you should find that there is a very important feature missing, i.e. ability to set your Out of Office while you are on the road. This application is designed to fill in this gap. More info over at ExtraComm [read] Keywords: domino lotus notes traveler application iphone office
48


IBM Lotus Domino iCalendar Meeting Request Parsing Remote Stack Buffer Overflow Vulnerability
Wed, Jul 20th 2011 6:21a   Dennis van Remortel
The solution in short: Upgrade to the latest version asap if you use iNotes outward facing. Some issues are fixed in 8.5.3, so beware until then. Bugtraq ID: 46232 Class: Input Validation Error CVE: CVE-2011-0915 Remote: Yes Local: No Published: Feb 07 2011 12:00AM Updated: Jul 20 2011 11:10AM Credit: anonymous Vulnerable: IBM Lotus Domino 8.0.2 IBM Lotus Domino 8.0.1 IBM Lotus Domino 7.0.4 IBM Lotus Domino 7.0.3 Fix Pack 1 (FP1) IBM Lotus Domino 7.0.3 IBM [read] Keywords: domino ibm inotes lotus notes security
77


IBM WebSphere Application Server JAX-RPC WS-Security/JAX-WS Runtime Security Bypass Vulnerability
Fri, Jun 17th 2011 12:19p   Dennis van Remortel
I just saw this in my RSS feeds: Bugtraq ID: 40322 Class: Design Error CVE: CVE-2010-0774 Remote: Yes Local: No Published: May 11 2010 12:00AM Updated: Jun 17 2011 04:00PM Credit: IBM Vulnerable: IBM Websphere Application Server 7.0.* IBM Websphere Application Server 6.1.* IBM Websphere Application Server 6.0.* IBM Tivoli Business Service Manager 4.2.1 (See full list in original document) Not Vulnerable: IBM Websphere Application Server 7.0 [read] Keywords: domino ibm application security server tivoli websphere
106


Security enhancements in iNotes 8.5.2 may require configuration changes in environments with reverse proxies
Fri, Jun 17th 2011 2:28a   Dennis van Remortel
I was playing with the application firewall in the citrix netscaler and I found a cookie I had never seen before to get blocked. Some quick googling gave me this Technote swg21453878. Please read it if you are using firewall/reverse proxy products in from of iNotes (or webadmin for that matter). Technote (troubleshooting) Problem Some security enhancements were introduced in iNotes 8.5.2 to prevent potential Cross Site Request Forgery (CSRF) attacks, and as part of these securi [read] Keywords: domino ibm inotes application citrix security server




Created and Maintained by Yancy Lent - About - Blog Submission - Suggestions - Change Log - Blog Widget - Advertising - FAQ - Mobile Edition