Vulnerability Development mailing list archives

Fwd: ShowFile CGI Security Vulnerability


From: SteeleIn99 () AOL COM (Barry Russell)
Date: Thu, 22 Jun 2000 00:50:32 EDT



<STRONG>attached mail follows:</STRONG><HR NOSHADE>
Today while messing around with a website who was running Apache WebServer
version 1.2.1 I came accross a file called showfile which was located in the
cgi-bin dir. This file is very dangerous. It allows the viewing of files on
your web system including /etc/motd,/etc/identd.conf and especially
/etc/passwd.

With the right/wrong(depends on the way you think about it) permissions you
can view the /etc/shadow file which is extremely dangerous. I dont know if
this file is shipped with the Apache server or not but I thought I would
report this anyway.

Update Your CGI Scanners :)

SteeLe


Current thread: