IBM DeveloperWorks ncp (Nigel's Capacity Planning) version 2.1 suffers from remote information disclosure vulnerabilities.
882d12c7145c7e3a4a8eef2d0d4490895d559af1506b25e96ecd08f8cea839a8
http://www.ibm.com/developerworks/systems/articles/free_tools/index.html
Can visit ncp pages and get info without authentication!
http://target:8282/
gives version
http://target:8282/real/lsconf.html
detailed config info including:
System Model
Machine Serial Number
Processor Type
Number of Processors
Processor Clock Speed
CPU Type
Kernel Type
LAPR Info
Memory Size
Firmware Version
Console Login (if enabled or not)
Auto Restart status
Host Name
Gateway IP
Name Server
Domain Name
Volume Group Info
http://target:8282/real.html
Graphs for host
File System Use
CPU Utilisation (User+System)