Re: Perl.exe and IIS security advisory

From: Tabor J. Wells (twellsat_private)
Date: Sun Jan 24 1999 - 17:23:40 PST

  • Next message: KuRuPTioN: "SSH Daemon"

    On Fri, Jan 22, 1999 at 08:58:33PM -0000,
    mnemonix <mnemonixat_private> is thought to have said:
    
    > In all versions of IIS, where a  website has been configured to interpret
    > perl scripts using the perl executable (perl.exe), a problem exists where a
    > request for a non-existent file will return the physical location on a disk
    > of a web directory. A request for:
    >
    > http://www.server.com/scripts/no-such-file.pl
    
    I really wish people wouldn't do this. www.server.com is a legitimate
    site (it's hosted on my network) and they certainly don't run IIS.
    
    Tabor
    Shore.Net
    --
    ___________________________________________________________________________
    Tabor J. Wells                                             twellsat_private
    Systems Administration Manager  Just another victim of the ambient morality
    Shore.Net  --  High quality Internet access and hosting services since 1993
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 14:30:39 PDT