[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] [Raq4] Directory Listing Exploit found.



> I know what you're thinking. "This has been addressed i the archives. You
> use: Options -Indexes in the access.conf file".
> However... This DOES work for normal directory listing. However... PHP
seems
> to bypass this. It has it's own permissions or something.
> So.. How do we make PHP abide by these rules too.. because this script i
> have can show u anyting

and the name of the script is?

a little favourite of mine is sysinfo/index.php which is a single file,
needs NO modification, just upload to anywhere on a  php server, and it
gives you all sorts of useful system information, you can see a demo running
at http://213.38.74.210/sysinfo/ on an old raq2 of mine