HTTP TRACE output...

From: ktos :) (maciek323_at_o2.pl)
Date: 08/29/03

  • Next message: Bryan: "device connection hijacking"
    To: <pen-test@securityfocus.com>
    Date: Fri, 29 Aug 2003 23:57:42 +0200
    
    

    Hi all.

    I used HTTP/1.1 TRACE and got such an output:

    --cut--
    TRACE / HTTP/1.1
    Host: host.com

    HTTP/1.1 200 OK
    Date: Fri, 29 Aug 2003 18:35:35 GMT
    Server: Apache
    Content-Type: message/http
    X-Cache: MISS from host.com
    Transfer-Encoding: chunked

    b9
    TRACE /web/ HTTP/1.1
    Connection: close
    Host: 10.10.5.121:6802
    X-Forwarded-For: 212.14.1.179, 212.14.1.179
    X-Forwarded-Host: 10.10.5.1
    X-Forwarded-Server: host.com

    0

    --cut--

    I am wondering is it possible to connect to other hosts in the subnet =
    using this host.com server...

    Best regards
    maciek323@O2.pl

    ---------------------------------------------------------------------------
    FREE Trial!
    New for security consultants and in-house pros: FOUNDSTONE PROFESSIONAL
    and PROFESSIONAL TL software. Fast, reliable vulnerability assessment
    technology powered by the award-winning FoundScan engine. Try it free for 21 days at: http://www.securityfocus.com/sponsor/Foundstone_pen-test_030825
    ----------------------------------------------------------------------------


  • Next message: Bryan: "device connection hijacking"

    Relevant Pages

    • Re: Problem with resolving own host name
      ... By "host name" I indeed meant the system name; ... Given that the resolver trace is as expected, it looks like a problem at ... name from a config member and resolves it via an external DNS server by ...
      (bit.listserv.ibm-main)
    • Re: Locating a server
      ... $ host opreview.net ... A trace blackholes in Los Angeles. ... why is it important that the server be 'off-shore'? ... that basement room is secret.. ...
      (alt.computer.security)
    • Re: Locating a server
      ... $ host opreview.net ... The IP address is assigned to Staminus Communications in Fullerton, CA, ... A trace blackholes in Los Angeles. ... why is it important that the server be 'off-shore'? ...
      (alt.computer.security)
    • Soft-Lockup/Race in networking in 2.6.31-rc1+195 (possibly caused by netem)
      ... The simplest policy I could reproduce the error with was: ... I also could reproduce the issue without netconsole but in vain of a serial console could not capture a trace. ... # CPUFreq processor drivers ... # PC SMBus host controller drivers ...
      (Linux-Kernel)
    • Re: www.google.com reference in directory-traversal attack
      ... If you put the dump into ethereal and trace the TCP stream you can see what's ... The top 3 lines are the request and the following ... specified either in the GET line or using the Host field. ...
      (Incidents)