Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email firstname.lastname@example.org
From: acz [iSecureLabs] (aurelien.cabezoniSecureLabs.com)
Date: Wed Aug 22 2001 - 09:28:49 CDT
-- [ iSecureLabs BadBlue v1.02 beta for Windows 98, ME and 2000
Advisory ] --
BadBlue v1.02 beta for Windows 98, ME and 2000 .php Source Code Disclosure
Problem discovered: 22/08/2001
-- [ Overview ] --
BadBlue is a tiny, free download that lets you share files, search other
PCs and even run powerful web applications.
Badblue support .php extension.
It is possible to retrieve full .php source code.
-- [ Description ] --
Badblue contains an input validation vulnerability which may lead to
download the full source code of .php pages.
This is due to a lack of checks for NULL bytes.
Note: It is possible too to download .dll file used by BadBlue.
-- [ Tested Version ] --
BadBlue v1.02 beta for Windows 98, ME and 2000
-- [ Fix ] --
According to BadBlue team, a fix will be included in the 1.5 version due
within the next week.
-- [ Discovered by ] --
Cabezon Aurélien | aurelien.cabezoniSecureLabs.com
http://www.iSecureLabs.com | French Security portal