Network Security Library
Javascript Feeds    RSS Feed    Security Dashboard    SearchSecurity.com
About | Contact | Advertise | Site Map
intrusion detection E-mail      Save Save This

Showcode.asp - A lesson in Internet Security


{LANG_NAVORIGIN} Web Security
02/18/2004



It all started back on May 7, 1999. Weld Pond of L0pht Heavy Industries issued a security advisory with the title "Web users can view ASP source code and other sensitive files on the web server." After first reading the advisory on BugTraq, I put together a small script that would go through a list of web sites and if they were IIS, check to see if showcode.asp was there. I fed it a list of urls I had gleaned from Yahoo.com and then watched in amazement as site after site came up positive for that vulnerability. Granted, this vulnerability was still very fresh but this is a sample file that is not even supposed to be on a production server. It was 9:00am Friday morning and I thought to myself that tens of thousands of companies were in for a surprise that day.

Read Entire Paper















E-Mail Link

Your IP address will be sent with this e-mail
From e-mail to e-mail



236 Views
0/5 Rating
0 Votes
Newest
Highest Rated
Most Viewed
Reference

Javascript Feeds
RSS (New Papers)
Security Dashboard

About SecurityDocs
Advertise
Contact

Valid HTML 4.01!
Valid CSS!


Unless otherwise noted, all paper copyrights are owned by the author. The rest copyright 2003-2005 TechTarget

Privacy : Contact