Re: Has anyone seen this?
Paul Schmehl <[email protected]> Thu, 25 Aug 2005 10:18:29 -0500
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <[email protected]> |
--On Thursday, August 25, 2005 09:43:03 -0400 Justin S <[email protected]> wrote: > > I have seen that before. I believe there was an old vulnerability in > IIS where you could modify your URL to have a bunch of ../ in it and > it would eventually take you back to the C drvie so you could then > move forward and access the winnt directory. You would have to have > an old and unpatched version of IIS to be vulnerable to it though. > Yes, but this didn't use directory traversal. That's what made it so odd and caught my attention. Paul Schmehl ([email protected]) Adjunct Information Security Officer University of Texas at Dallas AVIEN Founding Member http://www.utdallas.edu/ir/security/ _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions