Vulnerability Development mailing list archives

CGI insecurities


From: hypoclear () JUNGLE NET (hypoclear - lUSt - (Linux Users Strike Today))
Date: Mon, 24 Jan 2000 04:52:35 -0000


I have a question about CGI insecurities.  Let's suppose this...  Your looking at a site with some CGI forms that do a 
couple of neato things, and most likely there is a vulnerability in these scripts.  How would one go about exploiting 
these scripts?  (I'm not talking about pumping 1000 A's into it, till it crashes. ;-)  Do you need the source code for 
the script?  Is there anyway to retrieve the code of the working script on the site?  I'm posting to vuln-dev because I 
believe that it will help aid in the exploiting of CGI scripts...  of course I could be wrong :-)


Current thread: