This Metasploit module extracts usernames using the IBM Lotus Notes Sametime web interface using either a dictionary attack (which is preferred), or a bruteforce attack trying all usernames of MAXDEPTH length or less.
9197c678abfd9c900269d06122e761b5dace0fcb1d702aca5d7b66daa70838e7
This Metasploit module bruteforces Sametime meeting room names via the IBM Lotus Notes Sametime web interface.
7ffbd921baa1a67ca05c68d89620f4990b21816924913563d72365ae86ef1ab9
This Metasploit module scans an IBM Lotus Sametime web interface to enumerate the applications version and configuration information.
365f677622f89bc25680cef77c340b9c092065067cc3ff710bab8985bc653eae
This Metasploit module exploits a known flaw in the IBM Lotus Sametime WebPlayer version 8.5.2.1392 (and prior) to cause a denial of service condition against specific users. For this module to function the target user must be actively logged into the IBM Lotus Sametime server and have the Sametime Audio Visual browser plug-in (WebPlayer) loaded as a browser extension. The user should have the WebPlayer plug-in active (i.e. be in a Sametime Audio/Video meeting for this DoS to work correctly.
1a6622321e9e75594325110d9323a97ece910954ac54b5f2849094ab8f9f6920