Vulnerability Development mailing list archives

wwwboard my help reveal user name and password


From: jlinton () CIS FAMU EDU (Julian Linton)
Date: Fri, 7 Jul 2000 03:00:37 -0400


This is probably well know already. if wwwboard.pl is install with most of it default settings any web user can access 
www.somesite.com/wwwboard/passwd.txt
this will show the username and encrypted password for the wwwadmin.pl script.  I did a search on the internet and many 
of the site that are running wwwboard use the same password and username for other service, such as ftp or telnet.  I 
feel this can be a problem since the passwd.txt file is world readable.

Julian Linton
CIS Student @ FAMU.EDU
jlinton () cis famu edu


Current thread: