Abyss Web Server version 1.0.3 shows file and directory content

From: Securiteinfo.com (webmaster@securiteinfo.com)
Date: 07/29/02


From: Securiteinfo.com <webmaster@securiteinfo.com>
To: bugtraq@securityfocus.com
Date: Mon, 29 Jul 2002 19:56:42 +0200

Abyss Web Server version 1.0.3 shows file and directory content

.oO  Overview Oo.
Abyss Web Server version 1.0.3 shows file and directory content
Discovered on 2002, June, 30th
Vendor: Aprelium

Abyss Web Server 1.0.3 is a free personal web server available for Windows
and Linux operating systems. This web server can show file and directory
content. Only Windows version of Abyss is vulnerable.

.oO  Details Oo.
When sending a GET request with more than 256 slashes ("/"), then the server
shows all files in the directory content.
A hacker can see all hidden (non-HTML linked) files and directories on the
server.
This work only on Windows platforms. On Linux platform, this request is
handled, and return a 414 (Request-URI Too Large) error.

.oO  Solution Oo.
The vendor has been informed and has solved the problem.
Download Abyss Web Server 1.0.7 at :
http://www.aprelium.com/news/abws107tp.html

.oO  Discovered by Oo.
Arnaud Jacques aka scrap
webmaster@securiteinfo.com
http://www.securiteinfo.com



Relevant Pages

  • Abyss Webserver 1.0 Administration password file retrieval exploit
    ... Abyss Web Server was just released April 3rd. ... a request to get the password file just by breaking WWWROOT using Unicode. ... Abyss Web Server 1.0 Download password file to gain admin access ... Windows 98 ...
    (Bugtraq)
  • RE: asp.net 1.1 would not start: web server is not running 1.1
    ... request for a non-existent file called get_aspx_ver.aspx. ... | Thread-Topic: asp.net 1.1 would not start: web server is not running 1.1 ... | Content-Type: text/plain; ... | my windows and IIS running for a while and VS.Net is a new install. ...
    (microsoft.public.dotnet.framework.aspnet)
  • [VulnWatch] Abyss Web Server version 1.0.3 shows file and directory content
    ... Abyss Web Server version 1.0.3 shows file and directory content ... Abyss Web Server 1.0.3 is a free personal web server available for Windows ... When sending a GET request with more than 256 slashes, ...
    (VulnWatch)
  • Re: Loading windows xp...
    ... To see what NT services are rolled up into each instance of svchost, you need to use Process Explorer from SysInternals. ... You only need to have this NT service enabled and running if you use the firewall included in Windows or you run ICS. ... You might be able to use msconfig.exe or AutoRuns to find a startup entry for this. ... I have to wonder why you cannot decipher your own startup and running processes if you have the wherewithall to manage a web server and its pages. ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: Application pool terminated unexpectedly
    ... Things that can be responding to the request include: ... pool 'DefaultAppPool' terminated unexpectedly. ... We have always used Nessus for this. ... condition where almost every scan I run against the rebuilt web server ...
    (microsoft.public.inetserver.iis)