Nessus
[Top] [All Lists]

Re: Plugin 10297

To: Nessus@list.nessus.org
Subject: Re: Plugin 10297
From: Michel Arboi <mikhail@nessus.org>
Date: Sun, 18 Feb 2007 10:48:32 +0100
Cc:
Delivered-to: sp-com-lists@consult.net
Delivered-to: nessus-list1@securepoint.com
Delivered-to: Nessus@list.nessus.org
In-reply-to: <45D5CD1B.5090202@tenablesecurity.com> (George A. Theall's message of "Fri, 16 Feb 2007 10:26:19 -0500")
List-archive: <http://mail.nessus.org/pipermail/nessus>
List-help: <mailto:nessus-request@list.nessus.org?subject=help>
List-id: Discussion of Nessus software <nessus.list.nessus.org>
List-post: <mailto:nessus@list.nessus.org>
List-subscribe: <http://mail.nessus.org/mailman/listinfo/nessus>, <mailto:nessus-request@list.nessus.org?subject=subscribe>
List-unsubscribe: <http://mail.nessus.org/mailman/listinfo/nessus>, <mailto:nessus-request@list.nessus.org?subject=unsubscribe>
References: <9B71985304C4914AACE30A5BD6A08771351BDA@sumac.cfs.le.ac.uk> <45D5CD1B.5090202@tenablesecurity.com>
Sender: nessus-bounces@list.nessus.org
User-agent: Gnus/5.1008 (Gnus v5.10.8) Emacs/21.4 (gnu/linux)
On Fri Feb 16 2007 at 16:26, George A. Theall wrote:

> It probably is a browser issue -- some exploits are sensitive to the
> format of the request, and browsers can encode the URLs before sending
> them.

IIRC, it is not really a matter of "encoding", but rather the browser
simplifying the request by striping useles /../

> To be sure, you could test by telnet'ing into the web server and
> issuing the command by hand.

Telnet might fail in some cases. Netcat is better:
echo -e 'GET ..\\..\\..\\..\\..\\..\\windows\\win.ini HTTP/1.1\r\nHost: 
IP\r\n\r\n' | nc IP 80


-- 
http://www.bigfoot.com/~arboi           http://ma75.blogspot.com/
PGP key ID : 0x0BBABA91 - 0x1320924F0BBABA91
Fingerprint: 1048 B09B EEAF 20AA F645  2E1A 1320 924F 0BBA BA91
_______________________________________________
Nessus mailing list
Nessus@list.nessus.org
http://mail.nessus.org/mailman/listinfo/nessus

<Prev in Thread] Current Thread [Next in Thread>