Hello,

I'm sure this is known about,  but i noticed if you access urls directly on
the pfsense box,  you can by pass AAA (when using local db at least).

for example,  loading:

http://10.111.23.1/lightsquid/index.cgi

will take you to the reports page without being prompted for credentials.


have a great day,
greg

version:
*2.0-RC3 * (i386)
built on Wed Sep 7 13:03:07 EDT 2011

=================
_______________________________________________
List mailing list
[email protected]
http://lists.pfsense.org/mailman/listinfo/list

Reply via email to