[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [cobalt-users] [Raq4] Directory Listing Exploit found.
- Subject: Re: [cobalt-users] [Raq4] Directory Listing Exploit found.
- From: "GF" <error404@xxxxxxxxxxxxxx>
- Date: Sun Mar 24 17:19:19 2002
- List-id: Mailing list for users to share thoughts on Cobalt products. <cobalt-users.list.cobalt.com>
> I know what you're thinking. "This has been addressed i the archives. You
> use: Options -Indexes in the access.conf file".
> However... This DOES work for normal directory listing. However... PHP
seems
> to bypass this. It has it's own permissions or something.
> So.. How do we make PHP abide by these rules too.. because this script i
> have can show u anyting
and the name of the script is?
a little favourite of mine is sysinfo/index.php which is a single file,
needs NO modification, just upload to anywhere on a php server, and it
gives you all sorts of useful system information, you can see a demo running
at http://213.38.74.210/sysinfo/ on an old raq2 of mine