RE: directory traversal

From: antoine Bour (antoine.bour@par.sita.int)
Date: 02/08/02


From: "antoine Bour" <antoine.bour@par.sita.int>
To: <vuln-dev@securityfocus.com>
Date: Fri, 8 Feb 2002 09:57:21 +0100

and this one ... W2K SP2 + all hotfixes

c:\winnt>cd
............................................................................
............................................................................
.........................................................\

c:\winnt>cd system32
le chemin d'accès spécifié est introuvable

c:\winnt>cd \winnt\system32

c:\winnt\system32>

mystery ...when you find us!
it seems that cd \XXXX reset the bug ...

fun only or more ...?

-----Original Message-----
From: Steve [mailto:steve@frij.com.au]
Sent: vendredi 8 février 2002 00:29
To: vuln-dev@securityfocus.com
Subject: Re: directory traversal

Check out the change to CAPITAL as well; just to add to the mistery.

C:\windows\system32>cd
.........................................................
............................................................................
....
............................................................................
....
........\

C:\WINDOWS\SYSTEM32>cd \

C:\>cd windows\system32

C:\WINDOWS\SYSTEM32>

___________________________________________________________

This is true for me too

C:\WINNT\system32>cd \.........\

C:\>cd winnt\system32
The system cannot find the path specified.



Relevant Pages

  • Re: cciss: WARNING/BUG in do_cciss_intr (its back)
    ... I think this is a different bug than the one you reported previously. ... up completions from the previous kernel, due to the device not actually being reset. ... Some of them can be reset by using the "doorbell" register, and a patch ... which is one patch in a series of other patches to hpsa. ...
    (Linux-Kernel)
  • Re: Warning on migrating to ATMega8515 - eeprom problem
    ... >> Yes, probably a bug, but it is questionable if it is serious. ... >> It is generally a good practice to avoid relying on reset values. ... Conditional compilation is one way. ... You can thus run the compiled result of the same source code on both CPUs ...
    (comp.arch.embedded)
  • Re: I pedaled over 3200 pounds!
    ... By the way, if I'm not mistaken, slightly earlier in the video, ... powered snake that follows after my contraption, ... I hope you all had such a fun New Year's celebration! ... Typoes are not a bug, ...
    (rec.bicycles.tech)
  • Re: Sound problem no speakers
    ... tried alsactrl init (to reset everything. ... No joy on reboot. ... FOr anyone interested, it is Bug #74289. ...
    (Ubuntu)
  • Re: DELETE Trigger that will only allow cascading deletes
    ... I already found and fixed one bug in the code (but it will be some time ... I figured a trigger would both prevent the data loss next time, ... > mystery!) ... is if the record is deleted as part of a cascading ...
    (microsoft.public.sqlserver.programming)