Cgi-bin Shows password files in Cobalt Linux

From: magnet0 (magnet0at_private)
Date: Wed Jan 02 2002 - 16:43:32 PST

  • Next message: ByteRage: "Re: Clicktilluwin DLDER Trojan"

    
     ('binary' encoding is not supported, stored as-is)
    In many (im not sure if all) Cobalt Linux release 6.0 (Shinkansen) sytems, i have found that in the directory cgi-bin you can find several files such as "default.pass" that contains encrypted passwords and also you can find log files or others.
    
    It is very simple: (the server must be cobalt linux realease 6.0)
    
    www.xxxxx.com/cgi-bin
    
    There you will find a lot of files that can compromise the system.
    



    This archive was generated by hypermail 2b30 : Wed Jan 02 2002 - 21:27:45 PST