[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [cobalt-developers] Chili!Soft ASP Multiple Vulnerabilities



>I went into the control panel and selected ASP Administrative Server
>Properties - Parameters
>
>The server is running, and I'm now at
>http://myipnumber:5100/caspadmin/server.props.asp?server=%2Fhome%2F
>chiliasp%2Fasp%2Dapache%2D3000
>> 
>> You did substitute <server> for your server name right? <g>
>> And inclue the /service.pwd ?
>> And have the ASP server running?
>
>And then I pasted in the  example you gave after the 5100
>http://myipnumber:5100/caspsamp/codebrws.asp?source=/caspsamp/../admin/conf
>/service.pwd
>
>And got
>The requested URL /caspsamp/codebrws.asp was not found on this server.
>
>Additionally, a 404 Not Found error was encountered while trying to use an
>ErrorDocument to handle the request. 
>
>So...it doesn't act, at least as far as I can tell, as deatiled in the
>post.
>
>Thom

The problem is resolved deleting the sample code. It's possible you have
a newer Raq4 and the problem was resolved before it shipped. Mine are older and
as they were ran all the example exploits.