mailing list archives
ASP Security Hole (fwd)
From: bgreenbaum () SECURITYFOCUS COM (bgreenbaum () SECURITYFOCUS COM)
Date: Wed, 9 Feb 2000 16:21:57 -0800
Forwarded with permission of the author. Please direct all replies to
jwalsh () jwsg com
Director of Site Content
---------- Forwarded message ----------
Active server pages (ASP) with runtime errors
expose a security hole that publishes
the full source code name to the caller.
If these scripts are published on the
internet before they are debugged by
the programmer, the major search
engines index them. These indexed
ASP pages can be then located with a
simple search. The search results publish
the full path and file name for the ASP
scripts. This URL can be viewed in a browser
and may reveal full source code with
details of business logic, database location
- In the Altavisa search engine execute a search for
+"Microsoft VBScript runtime error" +".inc, "
- Look for search results that include the full
path and filename for an include (.inc) file.
- Append the include filename to the host name
and call this up in a web browser.
Exposes database connections and properties, resource locations,
cookie logic, server IP addresses, business logic
Exposes database properties, business logic
Exposes cobranding business logic
Exposes datafile locations and structure
Exposes source code for StoreFront 2000 including
Exposes search engine log
Exposes members email addresses and
private comments file http://www.wcastl.com/flat/comments.txt
Exposes cookie logic
- Search engines should not index pages that
have ASP runtime errors.
- Programmers should fully debug their ASP
scripts before publishing them on the web
- Security administrators need to secure
the ASP include files so that external users
can not view them.
JW's Software Gems
Email jwalsh () jwsg com
Phone (949) 855-0233
- Re: RFP2K01 - "How I hacked Packetstorm" (wwwthreads advisory), (continued)