OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: Showcode.asp
From: JULIAN LINTON (jlintonCIS.FAMU.EDU)
Date: Wed May 17 2000 - 12:26:28 CDT


I don' t think that there are any one file that can give complete access to
the server, but the information gained from showcode.asp help you find more
files that my have password in plaintext or other machines and such. Please
someone correct me if I may be off.

----- Original Message -----
From: Seth Georgion <sysadminSASSPRODUCTIONS.COM>
To: <FOCUS-MSSECURITYFOCUS.COM>
Sent: Tuesday, May 16, 2000 11:33 AM
Subject: Showcode.asp

> Sorry to bring this up again but in light of the new article on Security
Focus...
>
> If I was running showcode.asp, or any of the variants, besides connection
strings in ASP scripts, what is it that anybody could really see. The
article repeatedly mentions the tons of servers cracked and how easy it is
to crack a system running showcode but how easy is it really? I mean what
file is he referring to that anybody can get with Showcode and thus
completely take over a server?
>