Groups
Conversations
All groups and messages
Send feedback to Google
Help
Training
Sign in
Groups
MochiWeb
Conversations
About
Arbirary file access possible on Windows
28 views
Skip to first unread message
Sriram Melkote
unread,
Dec 14, 2012, 5:56:25 PM
12/14/12
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to moch...@googlegroups.com
Hi,
On Windows, it is possible to access arbitrary files by crafting a GET with unescaped backslash characters. Please see below for an example. This was raised in
http://www.couchbase.com/issues/browse/MB-7390
. I've made a possible fix for this,
https://github.com/melkote/mochiweb/commit/ac2bf
Thanks,
Sriram
GET /..............\ff\asubdir\secretfile
HTTP/1.1 200 OK
Server: MochiWeb/1.0 (Any of you quaids got a smint?)
Content-Type: text/plain
Content-Length: 14
Hello
World
Reply all
Reply to author
Forward
0 new messages