Bugtraq mailing list archives

Re: extra long URL attack


From: john () loverso southborough ma us (John Robert LoVerso)
Date: Sat, 11 Jan 1997 11:52:05 -0500


but this extra long URL to my site running
       Server version Stronghold/1.3 Ben-SSL/1.3 Apache/1.1.1.
will show you the raw contents of the top directory

You're was the only server (that I tried) that this worked on.  In particular,
it does not work against Apache/1.2bX sites, including:

        Server: Stronghold/2.0b1 Apache/1.2b2

John



Current thread: