Re: Major Security Hole IIS NT
This WebDNA talk-list message is from 1998
It keeps the original formatting.
numero = 18605
interpreted = N
texte = great idea but unfortunately the include tag will point to the filelocation that they can go to and look at it there.RayAt 04:04 PM 7/2/98, you wrote:>Another work around is to creat a file that has the search code it it and>use the include tad. That way all they will see is the tag.>>>>At 11:13 AM 7/2/98, you wrote:>>IIS reveals all special CGI Code>>>>Think no one can read your contextual searches, think again.>>>>Hit your webpage on an IIS server>>>>like http://www.yourdomain.com/special.tpl>>>>now try it like this>>>>http://www.yourdomain.com/special.tpl::$DATA>>>>All source code is revealed, even the special webdna data,>>>>this applies to all special CGI's running on IIS like ASP and Pearl. Try it.>>Hit your favorite microsoft server and add the url ::$DATA and you will see>>the special source code.>>>>Look here, this page is running Microsofts ASP and you can read it all.>>>>heheheh Pretty cool>>>>http://backoffice.microsoft.com/downtrial/default.asp::$DATA>>>>bummer is it also works on .tpl and the rest as well, I don't know about the>>encrypted pages available with 3.0 but I would be interested in hearing from>>others.>>>>Robert Minor>>Cybermill Communications>> > WebmasterMind Information Systemshttp://www.mindinfo.com
Associated Messages, from the most recent to the oldest:
great idea but unfortunately the include tag will point to the filelocation that they can go to and look at it there.RayAt 04:04 PM 7/2/98, you wrote:>Another work around is to creat a file that has the search code it it and>use the include tad. That way all they will see is the tag.>>>>At 11:13 AM 7/2/98, you wrote:>>IIS reveals all special CGI Code>>>>Think no one can read your contextual searches, think again.>>>>Hit your webpage on an IIS server>>>>like http://www.yourdomain.com/special.tpl>>>>now try it like this>>>>http://www.yourdomain.com/special.tpl::$DATA>>>>All source code is revealed, even the special webdna data,>>>>this applies to all special CGI's running on IIS like ASP and Pearl. Try it.>>Hit your favorite microsoft server and add the url ::$DATA and you will see>>the special source code.>>>>Look here, this page is running Microsofts ASP and you can read it all.>>>>heheheh Pretty cool>>>>http://backoffice.microsoft.com/downtrial/default.asp::$DATA>>>>bummer is it also works on .tpl and the rest as well, I don't know about the>>encrypted pages available with 3.0 but I would be interested in hearing from>>others.>>>>Robert Minor>>Cybermill Communications>> > WebmasterMind Information Systemshttp://www.mindinfo.com
Raymond Hatch
DOWNLOAD WEBDNA NOW!
Top Articles:
Talk List
The WebDNA community talk-list is the best place to get some help: several hundred extremely proficient programmers with an excellent knowledge of WebDNA and an excellent spirit will deliver all the tips and tricks you can imagine...
Related Readings:
Authorize.Net down 2 days in row (2004)
[searchString] (1997)
PCS Frames (1997)
No luck with taxes (1997)
Please, no more comparisons between operating systems (1998)
Where is f2? (1997)
2.0.1 new commands and contexts (1997)
Document Contains No Data! (1997)
RE: 2nd WebCatalog2 Feature Request (1996)
Document Contains No Data! (1997)
WC2.0 Memory Requirements (1997)
Help Wanted - Stowe, Vermont (1999)
Bug Report, maybe (1997)
Closest non matching search (2004)
limitation found on group searching (1997)
Separate SSL Server (1997)
4.0 send email ticks. . (2000)
[shownext max=?] armed (1997)
creating a 60 fields database (1997)
Can't save email prefs (2003)