Bugtraq mailing list archives
Disable Parent Paths
From: RZacha1 () TANDY COM (Robert Zachary)
Date: Mon, 31 Jan 2000 09:37:47 -0600
Writing a new IIS policy : summary: Parent Paths allows you to use '..' in calls to MapPath and the like. By default this option is enabled and should be disabled. To disable this option go to the root of the Web site in question, right click select Properties | Home Directory | Configuration | App Options and uncheck Enable Parent Paths. my question: What security hole/hack does this create if left enabled?. Rob
Current thread:
- Re: Future of s/key (Re: S/Key & OPIE Database Vulnerability) der Mouse (Jan 27)
- rzsz emails usage stats without user consent Kris Kennaway (Jan 29)
- Re: Future of s/key (Re: S/Key & OPIE Database Vulnerability) Greg A. Woods (Jan 29)
- RedHat 6.1 /and others/ PAM Michal Zalewski (Jan 30)
- Disable Parent Paths Robert Zachary (Jan 31)