cobalt.webmail.txt
来自「一个FTP密码破解程序的源代码」· 文本 代码 · 共 20 行
TXT
20 行
I just got a new Cobalt Cube today and I have been poking around at itfor security issues... I noticed this minor issue in the webmail system.Your users are not aloud to have shell access by default however if theymalform their mailbox requests they can read local files with the permsof the webserver. If your users have shell access they will not reallybe gaining anything however this could be used to remotely gatherinformation for a future attack. [admin admin]$ uname -aLinux cube.ckfr.com 2.2.16C7 #1 Fri Sep 8 15:58:03 PDT 2000 i586 unknown[admin admin]$ cat /etc/issue Cobalt Linux release 6.0 (Carmel)Kernel 2.2.16C7 on an i586http://YOURCOBALTBOX:444/base/webmail/readmsg.php?mailbox=../../../../../../../../../../../../../../etc/passwd&id=1-KF
⌨️ 快捷键说明
复制代码Ctrl + C
搜索代码Ctrl + F
全屏模式F11
增大字号Ctrl + =
减小字号Ctrl + -
显示快捷键?