|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
ASP vulnerability with Alternate Data Streams
Aleph One (aleph1
DFW.NET)Wed, 1 Jul 1998 21:37:29 -0500
- Messages sorted by: [ date ][ thread ][ subject ][ author ]
- Next message: Aleph One: "Re: Alert: Microsoft Security Notification service"
- Previous message: George Clooney: "Sun libnsl lameness"
---------- Forwarded message ---------- Date: Tue, 30 Jun 1998 15:27:32 +0200 From: Paul Ashton <paulARGO.DEMON.CO.UK> To: NTBUGTRAQ
LISTSERV.NTBUGTRAQ.COM Subject: ASP vulnerability with Alternate Data Streams Following on from the last .asp vulnerability which applied to URLs ending in spaces, and the previous that allowed .asps to be read if they end in ".", it turns out that there is yet another due to Alternate data streams. The unnamed data stream is normally accessed using the filename itself, with further named streams accessed as filename:stream. However, the unnamed data stream can also be accessed using filename::$DATA. If you open http://somewhere/something.asp::$DATA it turns out that you will be presented with the source of the ASP instead of the output. Deja vu?! It is left as an exercise for the reader to thing of further implications in other programs running on NT. Obviously, anything that to tries to restrict access based on filename instead of ACLs is going to have a hard time after this and the other recent revelations. Paul
- Next message: Aleph One: "Re: Alert: Microsoft Security Notification service"
- Previous message: George Clooney: "Sun libnsl lameness"