_
The Translate:f Security Hole
Recently a Windows 2000 / IIS 5 security hole was discovered that allows the source of ASP pages to be viewed through a simple HTTP request. This special HTTP request simply needs to be directed to an ASP page that is hosted on a Windows 2000 box that does not have either the security hole patch or Service Pack 1 installed. What makes this HTTP request special is that the ASP page being requested ends with a backslash and the HTTP header Translate: f is sent along. You can see ASP code that sends such a request at:
URL: http://www.4guysfromrolla.com/webtech/081500-1.shtml
_
Cost: N/A Platforms: N/A Version: N/A
From: Security Systems
You are here: Top ::
ASP > Scripts & Programs > Security Systems
| Rate
The Translate:f Security Hole |
____
There are currently no comments available.
|