Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Coldfusion Path Disclosure Vulnerability, Help Required |
|---|---|
| Date: | Sat, 26 Feb 2005 03:18:04 +0530 |
Respected Members, A Few days ago when i was doing a routine scan of my brother's website for finding out vulnerabilities, Nikto reported this vulnerability "nul..dbm - ColdFusion 5.0 and below, 4.0-5.0 reveal file system paths of .cfm or .dbm files when the request contains invalid DOS devices." and i checked Bugtraq Archives for more info on this and i got the following info that "Certain Requests for certain DOS-devices are parsed by the isapi filter that handles .cfm and .dbm and result in error messages containing the physical path to the web root." and when i tried the above vulnerability and requested for a nul.dbm file on the website, i got the following which indeed revealed the path to the web root Here is what i saw (changed the name of the site to protect private info) The requested file "F:\webcorp\acme.com\nul.dbm" cannot be found. The specific sequence of files included or processed is: F:\webcorp\acme.com\nul.dbm Bugtraq says that this is called an Input validation error and is very critical and must be patched.. What i wanted to know know how this vulnerability can result in more harm, i mean after exploiting it all i got to know is the path and nothing else, now at this point how an attacker can really exploit this vulnerability and gain access to the web site or deface it?? in short How is it possible for an attacker to compromise the server or deface the site when only the physical path is known. Any responses with exploit examples would be highly appreciated as that would help me test the exploit and prove that this is indeed a red alert sign and should be patched immediately. Thanking you Maverick_12210
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: tool to log file access, Jeff Gercken |
|---|---|
| Next by Date: | Webhits.dll arbitrary file retrieval Vulnerability, hel Required, Maverick The Techie |
| Previous by Thread: | Source code auditing tools capabilities and evaluation, Source Auditor |
| Next by Thread: | Webhits.dll arbitrary file retrieval Vulnerability, hel Required, Maverick The Techie |
| Indexes: | [Date] [Thread] [Top] [All Lists] |