Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



WebApp Sec: Mambo File Inclusion Attacks

Mambo File Inclusion Attacks

From: Mark Ryan del Moral Talabis <talabis_at_gmail.com>
Date: Sun, 15 Jan 2006 20:23:15 +0800

We have been receiving multiple attacks directed towards the popular
open source portal and content management system, Mambo. The attacks
makes use of the "mosConfig_absolute_path" file inclusion
vulnerability of certain unpatched versions of the said application.
In this case, a possibly malicious file called "micu" is downloaded in
the process of the attack.

Full analysis:
http://www.philippinehoneynet.org/data.php

Ryan Talabis
Lead Analyst
Philippine Honeynet Project
http://www.philippinehoneynet.org

-------------------------------------------------------------------------
This List Sponsored by: Watchfire

Watchfire's AppScan is the industry's first and leading web application
security testing suite, and the only solution to provide comprehensive
remediation tasks at every level of the application. See for yourself.
Download AppScan 6.0 today.

https://www.watchfire.com/securearea/appscansix.aspx?id=701300000003Ssh
--------------------------------------------------------------------------
Received on Jan 15 2006

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]