lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20090210203424.4647.qmail@securityfocus.com> Date: 10 Feb 2009 20:34:24 -0000 From: cxib@...urityreason.com To: bugtraq@...urityfocus.com Subject: Re: PHP filesystem attack vectors try combination with ..\ \ is accepted in many linux distr. Some time ago, was possible bypass safe_mode. like include "..\..\..\..\..\..\../../../../../etc/passwd" We do not guarantee that it still works. -- Best Regards, ------------------------ pub 1024D/A6986BD6 2008-08-22 uid Maksymilian Arciemowicz (cxib) <cxib@...urityreason.com> sub 4096g/0889FA9A 2008-08-22 http://securityreason.com http://securityreason.com/key/Arciemowicz.Maksymilian.gpg