Re: [Full-disclosure] Bug with .php extension?



z3n wrote:
> Great Bug indeed!
>
> But don't you think this issue is kind of similar to issue 3 in this
> (old) advisory:
> http://archives.neohapsis.com/archives/bugtraq/2003-01/0203.html
>

Well, actually, I think this is some kind of "feature" and is associated with
the behavior that is i.e. demonstrated on default installations of Apache (which
have several index.html index.html.de .en .jp etc.), only that this time not
mod_negotiation, but mod_mime is responsible.

--ck
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



Relevant Pages

  • Re: [Full-Disclosure] when will IE exploits COME TO AN END...
    ... INDEED A BUG BUT i got lot of flamings ... ... while trying to explain one of my advisory to some 31337's. ... Charter: http://lists.netsys.com/full-disclosure-charter.html ...
    (Full-Disclosure)
  • Re: [Full-disclosure] Windows O/S
    ... I guess that is the remaining of an old IE bug that opened notepad.exe on the desktop. ... Hosted and sponsored by Secunia - http://secunia.com/ ... Charter: http://lists.grok.org.uk/full-disclosure-charter.html ... Prev by Date: ...
    (Full-Disclosure)
  • Re: [Full-disclosure] Facebook Attach EXE Vulnerability
    ... Nice bug, and, atleast you worked with them to reproduce, you realise ... Full-Disclosure - We believe in it. ... Charter: http://lists.grok.org.uk/full-disclosure-charter.html ... Hosted and sponsored by Secunia - http://secunia.com/ ...
    (Full-Disclosure)
  • Re: [Full-disclosure] Facebook Attach EXE Vulnerability
    ... the bug hunting page (as with everywhere else, ... maintaining full-disclosure. ... Charter: http://lists.grok.org.uk/full-disclosure-charter.html ... Hosted and sponsored by Secunia - http://secunia.com/ ...
    (Full-Disclosure)
  • Re: [Full-disclosure] Facebook Attach EXE Vulnerability
    ... thanks for clearing it up, but sure, if theyre paying better now thats ... to reproduce the bug YOU made even, in order to _NOT_ pay you shit. ... Charter: http://lists.grok.org.uk/full-disclosure-charter.html ... Hosted and sponsored by Secunia - http://secunia.com/ ...
    (Full-Disclosure)