Synopsis: Novacoast has discovered a vulnerability in the Novell NetWare Operating System screen saver software. The vulnerability allows a local attacker to bypass authentication and access the system console. Description: The Novell Operating System uses the screen saver nlm with lock enabled to protect access to the console. When the screen saver is locked only a user in the e-directory tree with supervisor rights to the server object has the ability to unlock it. It is possible to bypass this authentication scheme by entering the debugger within NetWare while the screensaver is running, kill the screensaver process, and resume the operating system without the screen saver or the access control still running. Affected Version: Novell NetWare 5.1 Novell Netware 6 Novell NetWare 6.5 Exploit: with the screensaver nlm running and in enable lock mode press alt shift shift esc. Find the screen saver process in memory. Kill it using the debugger. If you are not sure how to use the NetWare debugger then just kill the server with the q key and restart it without the autoexec.ncf running (server -na) edit the autoexec.ncf to keep the screensaver from running in the future and restart the server normally. The screen saver will not start again. Search google for "rconsole nvl bypass" Before I continue with Netware security and how to bypass it, first I'm going to ... Just try to access the console with "rconsole.exe" to verify if those http://www.infosyssec.net/infosyssec/novsec1.htm