Skip to content
Permalink
main
Switch branches/tags
Go to file
 
 
Cannot retrieve contributors at this time
<html>
<body bgcolor="#FFFFFF">
<p align="center"><b><font size="2" face="Courier New, Courier, mono" color="#FF0000">Verb0
0wnZ YoU!</font><font size="2" face="Courier New, Courier, mono"><br>
<br>
</font></b></p>
<p align="left"><b><font size="2" face="Courier New, Courier, mono">Once, somebody
told me that Perl is LAME! I wrote an perl script that opens me a shell on port
...... And I saw all files on this server! (NOTE: I was not ROOT!). The &quot;/root&quot;
directory is world readable on all s??.virtualave.net servers. They are running
FreeBSD (i386) on all machines. Why is it so danger? For example user &quot;eleet&quot;
have an protected area on his site and the password is stored in the file &quot;/cgi-bin/password.txt&quot;
(Forbidden). All I have to do is: cat /home/eleet/cgi-bin/password.txt and that's
it.</font></b></p>
<p align="center"><b><font face="Courier New, Courier, mono" size="2" color="#FF0000">(:
CGI ACCESS IS VERY DANGER :)</font></b></p>
<br><br>
<center><pre>
Command: <a href="/uname">uname -a</a>
Command: <a href="/lsal">ls -al /</a>
</pre></center>
</body>
</html>
<!-- www.attrition.org web hack mirror - watermark or something -->