Page 1 of 2

Easter eggs? Funny stuff...

Posted: 14 Sep 2005 02:51
by alex
Just been doing some explorations on OXE 6.1.
Found a kinda funny thing.
You can try it on yours OXE and say what you see
Just put in any browser

[url]https://<Your_OXE_address>/wtool/html/tools.html[/url]

and see what you get :D

Posted: 17 Sep 2005 06:28
by alex
Some news.
If in previuos post you can use "mtcl" account then on following page I did not succeed to log on using all possible existing accounts - mtcl, root, swinst, adfexc.

[url]https://<YourOXEaddress>/webtools2/php[/url]

Any ideas?

Posted: 17 Sep 2005 22:58
by frank
Nice trick... I will try to hack it later tonight and give you answer or a bypass :-)

Posted: 19 Sep 2005 05:09
by alex
frank wrote:Nice trick... I will try to hack it later tonight and give you answer or a bypass :-)
OK.Basically accounts and passwords as I understand initialised in a file "SecurityManagerTestProgram.php"

Posted: 19 Sep 2005 20:27
by frank
OOppss, i forgot to check it out last night.. I'll do it tonight !

Posted: 19 Sep 2005 21:07
by frank
Ok, for the hack now... :-)


:arrow: Switch to root user

:arrow: go to /home/httpd/html/webtools2/php/WebToolsApp

:arrow: Edit the file WebToolsApp.phb

:arrow: Search for
if (!$this->security_manager->isAccepted($user_id))


and remove the !

Then take your favorite browser (Mozilla :-) ) and go to

https://Your_OXE_IP_Address/webtools2/php/index.php

Login with user mtcl and as a password mtcl ...

Enjoy !

Frank

Posted: 19 Sep 2005 21:11
by frank
PS: There are some other users that you can use. Go to the Authentication folder, and you'll see a file called UserAccountsAndProfiles.xml ... There are some restricted users too (root and alcatel) , and a new user that I never used: clark

Frank.

Posted: 20 Sep 2005 05:22
by alex
frank wrote:PS: There are some other users that you can use. Go to the Authentication folder, and you'll see a file called UserAccountsAndProfiles.xml ... There are some restricted users too (root and alcatel) , and a new user that I never used: clark

Frank.
Great! Thanks.I'll check it later this week

Posted: 20 Sep 2005 08:52
by vad
Hi, Alex
About webtools2 - this thing exist from release 6.1?

Posted: 26 Sep 2005 04:39
by alex
vad wrote:Hi, Alex
About webtools2 - this thing exist from release 6.1?
Hi
Actually I do not know.
Anyway these features(wtools and webtools) look like unfinished projects.
May be they have been closed or frozen.