Sunday 30th, November 2003
Password Recovery Tool11/30/2003 16:04
I was browsing the Internet looking for Lotus Notes related stuff as I found a tool used to recover lost passwords for Lotus Notes id files.
First I was shocked that there should be a flaw in the id files which would make it easy to find the users oder certifiers password, but then I had a closer look onto the tool and found that it is doing dictionary and bruteforce attacks. The maximum password length you can recover is 15 characters. Even with a fast computer (2GHz or more) you will calculate several days to even find a password with 6 characters. If you want to check for upper and lowercase too it will take even longer.
I can't see any danger for Administrators as they were always driven to use long, not predictable passwords for certifiers.
Tuesday 18th, November 2003
Remove a group from all your databases ACL?11/18/2003 07:23
I found that there is an unexpected but fast way to remove a group from every databases ACL in your Lotus Notes Domain. Just rename a group using the appropriate action in your Domino Directory and oops, as you didn't want to do that, just enter the old name of the group again. Everybody would expect AdminP to ignore this request as source and target name are the same but in fact AdminP removes the group!!!!
This Problem has been reported to Lotus Support and is fixed in Lotus Domino 6.5.
Saturday 15th, November 2003
Translation Problem in Lotus Notes Client11/15/2003 16:44
I heard about a strange Problem in the
Lotus Notes Client which should exist in all localized Versions beginning
with 6.0 up to version 6.5. As you can see on the screenshot of a repeating
calendar entry the weekdays are displayed in english language instead of
I heard rumors that customers, who are contacting the software vendor,
would get help but I can't go into detail here.
Wednesday 12th, November 2003
Murphy visited me on sunday11/12/2003 08:31
While I was enjoying the weekend Murphy visited my server to say hello. The harddisk crashed and my friends and me had to restore the whole server. For some strange reason I had a backup for nearly everything - except my own BLOG.