Full Disclosure mailing list archives
Re: [WEB SECURITY] Plain Old Webserver - The coolest firefox extension
From: ascii <ascii () katamail com>
Date: Mon, 12 Feb 2007 22:48:37 +0100
Billy Hoffman wrote:
All depends on in the request processing you apply the fix. Its possible that URL Decoding hasn't occuried yet, whereby I can bypass your filter pretty easily. Not to mention Unicode...
hehehe i was waiting for this : ) remember: this is funsec the bypass for the filter is in the signature of the same mail
path = str_replace('../', '', path); regards, Francesco 'ascii' Ongaro http://www.ush.it/ ..././..././..././..././ how can't you love funsec?
cause ..././..././..././..././ becomes ../../../../ since the replace is applied only once. simple logic trick, no encoding at all see you, Francesco 'ascii' Ongaro http://www.ush.it/ _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Plain Old Webserver - The coolest firefox extension pdp (architect) (Feb 09)
- Re: [WEB SECURITY] Plain Old Webserver - The coolest firefox extension Stefano Di Paola (Feb 09)
- Re: [WEB SECURITY] Plain Old Webserver - The coolest firefox extension pdp (architect) (Feb 10)
- Re: [WEB SECURITY] Plain Old Webserver - The coolest firefox extension ascii (Feb 09)
- Re: [WEB SECURITY] Plain Old Webserver - The coolest firefox extension Billy Hoffman (Feb 12)
- Re: [WEB SECURITY] Plain Old Webserver - The coolest firefox extension ascii (Feb 12)
- Re: [WEB SECURITY] Plain Old Webserver - The coolest firefox extension Giorgio Fedon (Feb 12)
- Re: [WEB SECURITY] Plain Old Webserver - The coolest firefox extension pdp (architect) (Feb 10)
- Re: [WEB SECURITY] Plain Old Webserver - The coolest firefox extension Stefano Di Paola (Feb 09)
- Re: [WEB SECURITY] Plain Old Webserver - The coolest firefox extension Matthew Flaschen (Feb 23)