Re: CGI security

From: Arturo Busleiman (buanzoxat_private)
Date: Tue Sep 14 1999 - 20:13:11 PDT

  • Next message: Brock Tellier: "SCO 5.0.x Xt lib exploit"

    > But  there  is  EOL  character ('\0'.). If you will use something like
    > "/index.html?%00xxxxxxxxxxxxxxxxx" xxxxxxxxxxxxxxxxx propably will not
    > appear in any logs at all.
    so, if I telnet localhost 80:
    Trying 127.0.0.1
    Connected to localhost
    Escape character is '^]'.
    GET /index.html?%00blabla
    
    OK, I get index.html..... but....
    
    # tail /var/log/messages/httpd.access_log
    localhost - - [15/Sep/1999:00:09:30 -0300] "GET /usa.html?%00blabla" 200 8944
    
    it does appear. did I missed something, or our assumptions were erroneous?
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 15:03:54 PDT