Full Disclosure mailing list archives
Re: Comdev One Admin 4.1 Remote File Inclusion
From: "Knud Erik Højgaard" <kokanin () gmail com>
Date: Wed, 18 Oct 2006 10:16:02 +0200
- requires register globals on - requires magic quotes off
Seriously, who gives a shit then? And who gives a rats ass about file inclusion in a crappy php script run only by you, your sister and the author? It's as useful as buffer overflows in non-suid binaries, akin to releasing advisories stating - requires user to download and execute binary - requires blank administrator password - requires chmod +s /bin/*
ADVISORY & EXPLOIT (requires registration): http://w4ck1ng.com/board/showthread.php?t=1491
BLA BLA HOW TO FIND BUGS LIKE THIS (requires lack of dayjob, desire for 'fame'): wget -m crappy-php-coders.com/stupid-scripts ; egrep -r 'include\(\$|require\(\$' . | bugtraq-mailer-including-selfpromotion-crap -- lol @ security 'industry', it's like printing ones own monies!!"3 _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Comdev One Admin 4.1 Remote File Inclusion disfigure (Oct 17)
- Re: Comdev One Admin 4.1 Remote File Inclusion Knud Erik Højgaard (Oct 18)
- Re: speaking of code crunching... (challenge) Peter Ferrie (Oct 18)