Major Security Hole IIS NT
This WebDNA talk-list message is from 1998
It keeps the original formatting.
numero = 18612
interpreted = N
texte = IIS reveals all special CGI CodeThink no one can read your contextual searches, think again.Hit your webpage on an IIS serverlike http://www.yourdomain.com/special.tplnow try it like thishttp://www.yourdomain.com/special.tpl::$DATAAll source code is revealed, even the special webdna data,this applies to all special CGI's running on IIS like ASP and Pearl. Try it.Hit your favorite microsoft server and add the url ::$DATA and you will seethe special source code.Look here, this page is running Microsofts ASP and you can read it all.heheheh Pretty coolhttp://backoffice.microsoft.com/downtrial/default.asp::$DATAbummer is it also works on .tpl and the rest as well, I don't know about theencrypted pages available with 3.0 but I would be interested in hearing fromothers.Robert MinorCybermill Communications
Associated Messages, from the most recent to the oldest:
IIS reveals all special CGI CodeThink no one can read your contextual searches, think again.Hit your webpage on an IIS serverlike http://www.yourdomain.com/special.tplnow try it like thishttp://www.yourdomain.com/special.tpl::$DATAAll source code is revealed, even the special webdna data,this applies to all special CGI's running on IIS like ASP and Pearl. Try it.Hit your favorite microsoft server and add the url ::$DATA and you will seethe special source code.Look here, this page is running Microsofts ASP and you can read it all.heheheh Pretty coolhttp://backoffice.microsoft.com/downtrial/default.asp::$DATAbummer is it also works on .tpl and the rest as well, I don't know about theencrypted pages available with 3.0 but I would be interested in hearing fromothers.Robert MinorCybermill Communications
Bob Minor
DOWNLOAD WEBDNA NOW!
Top Articles:
Talk List
The WebDNA community talk-list is the best place to get some help: several hundred extremely proficient programmers with an excellent knowledge of WebDNA and an excellent spirit will deliver all the tips and tricks you can imagine...
Related Readings:
Include a big block of text (1997)
Just a thought (1998)
2nd WebCatalog2 Feature Request (1996)
WebDNA 6 (2004)
multi-paragraph fields (1997)
Re:Signal Raised (1997)
Cart file not being written (2000)
[isfolder] and [filename] (1997)
PCS Frames (1997)
Problems adding stuff to the shopping cart. (1997)
Attention all list readers (1997)
Fwd: Handling Charges (1999)
Searching Multiple DBs (1997)
WebMerchant Error (1998)
Template Security error (1997)
Quotes inside alt tags (2008)
Card clearance, problems - solutions? (1997)
!!!!!!!!!!String Search!!!!!!!!!!!!!!!!!! (2001)
Languages (1997)
Credit Card not accepted (1998)