Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Pen-Test
[Top] [All Lists]

Coldfusion Path Disclosure Vulnerability-Help Required

Subject: Coldfusion Path Disclosure Vulnerability-Help Required
Date: Sat, 26 Feb 2005 03:17:14 +0530
Respected Members,

A Few days ago when i was doing a routine scan of my brother's
website for finding out vulnerabilities, Nikto reported this
vulnerability
"nul..dbm - ColdFusion 5.0 and below, 4.0-5.0 reveal file system
paths of .cfm or .dbm files when the request contains invalid DOS
devices." and i checked Bugtraq Archives for more info on this and i
got the following info that

"Certain Requests for certain DOS-devices are parsed by the isapi
filter that handles .cfm and .dbm and result in error messages
containing the physical path to the web root."

and when i tried the above vulnerability and requested for a nul.dbm
file on the website, i got the following which indeed revealed the
path to the web root

Here is what i saw (changed the name of the site to protect private
info)

The requested file "F:\webcorp\acme.com\nul.dbm" cannot be found.


The specific sequence of files included or processed is:
F:\webcorp\acme.com\nul.dbm

Bugtraq says that this is called an Input validation error and is
very critical and must be patched..

What i wanted to know know how this vulnerability can result in more
harm, i mean after exploiting it all i got to know is the path and
nothing else, now at this point how an attacker can really exploit
this vulnerability and gain access to the web site or deface it??
in short

How is it possible for an attacker to compromise the server or
deface the site when only the physical path is known.

Any responses with exploit examples would be highly appreciated as
that would help me test the exploit and prove that this is indeed a
red alert sign and should be patched immediately.

Thanking you

Maverick_12210

<Prev in Thread] Current Thread [Next in Thread>
  • Coldfusion Path Disclosure Vulnerability-Help Required, Maverick The Techie <=