Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: Re: Mandrake 5.3/7.0, RedHat 5.2/5.3/6.0 + Apache BUG

Re: Mandrake 5.3/7.0, RedHat 5.2/5.3/6.0 + Apache BUG

From: Daniel Garcia <dgarcia_at_HOLLYFELD.ORG>
Date: Tue, 1 Aug 2000 16:29:52 -0400

On Mon, 31 Jul 2000, Kasatenko Ivan Alex. wrote:
> Lately my users helped me (in a way the call this ``hacking'' :) to
> discover one unpleasant feature: a home catalog of ``nobody'' user is
> "/" on most Mandrake's and RedHat's (any others?) I've seen, and with
> such a setting in the httpd.conf (I assume this is typical?)...
> > # UserDir: The name of the directory which is appended onto a user's home
> > # directory if a ~user request is recieved.
> >
> > UserDir ./
> .. any user may go to, for example,
> http://www.malconfigured-host.com/~nobody/etc/ and get a list of files
> in the /etc catalog. I assume this a hole.

UserDir is actually typically set to public_html - or some such. I have
never seen a site setup with UserDir set to './' - but needless to say,
that's a Very Bad[tm] way to set things up.

I'm fairly certain that default installs of apache (and the distros that install
apache by default) have this set to public_html.

Cheers,

--Dg

                      Wir müssen wissen; wir werden wissen
     | http://hollyfeld.org | http://silentnoise.org | http://aumlaut.net |
          w | email/dgarcia_at_silentnoise.org | mp3/www.mp3.com/sol3 | g
            Listen to Silent Screams: http://silentnoise.org/screams
                  np on Silent Screams: Aumlaut 4.1 by Aumlaut
Received on Aug 02 2000

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos