A 2026 read of the Lotus Domino application-to-OS exploitation work originally published by DSecRG around 2009. The full piece lands in the next publication cycle. Filed under Heritage revisits.
The original work demonstrated a full chain from application-level Lotus Domino bugs (authentication primitives, parser flaws in the LotusScript runtime, file inclusion in the web client) down to OS-level command execution and persistence. At the time Domino was widely deployed in enterprise messaging and the research was a frequent reference in penetration-test reports.
In 2026 Domino is largely retired from enterprise environments (replaced by Exchange, then Microsoft 365), but the chain technique transferred. The full revisit will look at the modern descendants of the same exploit-class — XML/file-inclusion in mail-server admin consoles, deserialisation in Java mail clusters, and where the 2009 lessons apply to today’s HCL Notes / Domino-in-cloud deployments.
Original document preserved at the Internet Archive. The full 2026 revisit is on the schedule.