Go Back   Velocity Reviews > Newsgroups > Computer Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply

Computer Security - anyone heard of /escape vulnerability ?

 
Thread Tools Search this Thread
Old 08-13-2003, 09:23 AM   #1
Default anyone heard of /escape vulnerability ?



Hi !

We recently had a network audit conducted on our network and I could
access the oral report. Unfortunately, the contact dit not seem to know
much about what was being told so...

As the subject says, what is a "slash escape" vulnerabiltiy ? The audit
was made on a IIS server. Googel searches are quite complex with such
term as I have to find a "/escape" pattern... = (

..antoine




.Saphyr
  Reply With Quote
Old 08-13-2003, 05:57 PM   #2
Lord Shaolin
 
Posts: n/a
Default Re: anyone heard of /escape vulnerability ?
..Saphyr <> randomly produced:

:: Hi !
::
:: We recently had a network audit conducted on our network and I could
:: access the oral report. Unfortunately, the contact dit not seem to
:: know much about what was being told so...
::
:: As the subject says, what is a "slash escape" vulnerabiltiy ? The
:: audit was made on a IIS server. Googel searches are quite complex
:: with such term as I have to find a "/escape" pattern... = (
::
:: .antoine

I think you are possibly talking about breaking out of the root directory?

This is how most of the old web based exploits worked

e.g. on a Linux machine:

www.yourdomain.com/../../etc/passwd

or on Windows:

www.yourdomain.com/../../../WINNT/repair/sam

etc

Google a little on such things (Unicode exploits also work in a similar
fashion).

ST

--


..: http://www.security-forums.com :.

Share your knowledge
It's a way to achieve
Immortality.




Lord Shaolin
  Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Computer Security aldrich.chappel.com.use@gmail.com A+ Certification 0 11-27-2007 02:11 AM
has anybody heard from jefhew@rogers.com??????? the seeker A+ Certification 0 02-10-2004 10:47 PM
Excalibur - anyone heard anything? Phatty Boombatty DVD Video 11 02-10-2004 05:49 AM
Lord of the what ? Never heard of it. Peter DVD Video 17 12-22-2003 04:06 AM
Re: Does anyone ever heard about quality assurance in helpdesks? Pikoro A+ Certification 2 07-16-2003 03:24 AM




SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46