Vulnerability Development mailing list archives

Re: Reported Kazaa and Morpheus vulnerabilities


From: "HarryM" <harrym () the-group org>
Date: Mon, 4 Feb 2002 07:42:52 -0000

Well, I think that's what the original poster was getting at.  Anyone
here tried the usual .. bugs and so on?  (Either successfully or not,
we'd like to know.)


Exactly. The BBC article claims that someone has, but there's no mention of
it on CERT or Securityfocus. I mean obviously if there is one it may not
have been posted about.. But I thought someone might have heard something.
Certainly simple things such as appending /../ or /..../ to the end of the
url don't work, but those funky numeric folder names must mean something.

Harry M


Current thread: