Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Xoop |
|---|---|
| Date: | Wed, 30 Aug 2006 12:21:24 -0400 (EDT) |
Hello, I am pen testing a site and I found that it is running Apache/2.0.52 (Unix) mod_ssl/2.0.52 OpenSSL/0.9.7g PHP/5.0.4 mod_jk2/2.0.2 and Xoop(don't know what version yet) among other things. The core of the functionality I am testing is related to Xoop. I searched for bugs and all the other basic stuff. I noticed something interesting: https://www.AAAAAAAAAA.com/main/modules/mymenu/index.php?file=index.php so I tried https://www.AAAAAAAAAA.com/main/modules/mymenu/index.php?file=../../ And I get a 404 file not found instead of 403! With the exception of a few default apache DIRs listing is disabled but all I need is to navigate to a useful/interesting file. Anyone have any tips about Xoop? -- Vlad G. The information transmitted is intended only for the person or entity to which it is addressed and may contain confidential and/or privileged material. Any review, retransmission, dissemination or other use of, or taking of any action in reliance upon, this information by persons or entities other than the intended recipient is prohibited. If you received this in error, please contact the sender and delete the material from any computer.
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| Previous by Date: | need help with webgoat, Tomaz Korosec |
|---|---|
| Next by Date: | Re: Xoop, Vlad |
| Previous by Thread: | Enumerate Web Virtual Site, Roger Liu |
| Next by Thread: | Re: Xoop, Josh Zlatin-Amishav |
| Indexes: | [Date] [Thread] [Top] [All Lists] |