Another vulnerability in hosting controller

From: Bao Dai Nhan (baodainhanat_private)
Date: Sun May 19 2002 - 03:10:50 PDT

  • Next message: John Howie: "RE: Verisign PKI: anyone to subordinate CA"

    
     ('binary' encoding is not supported, stored as-is)
    1/If admin doesn't change or delete user AdvWebadmin, the 
    default password of this user is advcomm500349, you can 
    creat your own account or use this account to hack the 
    server.
    1/ A foolish vulnerability, i can view the harddisk by 
    using the file browse.asp in directory admin
    www.victim.com/admin/browse.asp?FilePath=c:\&Opt=2&level=0
    
    BAODAINHAN
    baodainhanat_private
    www.viethacker.net
    



    This archive was generated by hypermail 2b30 : Mon May 20 2002 - 11:46:08 PDT