Metasploit mailing list archives

bug in shttpd_post exploit


From: msairam at intoto.com (M P Sairam)
Date: Fri, 28 Mar 2008 12:37:13 +0530

Hi,
    There is a bug in shttpd_post script. In http request that is sent, 
the request method is in lowercase (post) but it should be in upper 
case. Even though the HTTP server accepts lower case request methods but 
according to rfc 3875, http request methods are case sensitive.

--Sairam

********************************************************************************
This email message (including any attachments) is for the sole use of the intended recipient(s) 
and may contain confidential, proprietary and privileged information. Any unauthorized review, 
use, disclosure or distribution is prohibited. If you are not the intended recipient, 
please immediately notify the sender by reply email and destroy all copies of the original message. 
Thank you.
 
Intoto Inc. 




Current thread: