Thread: What is an arbitrary file?

    s0nIc
    Question What is an arbitrary file?

    Shoot me in the foot for askin this.. but what is an arbitrary file? ive been lookin it up and cant find a clear definition.

    Well lets say if im on a site and im just fooling around looking for a few CGI flaws because we all know what an ******* I am... one flaw found allowed me to retrieve arbitrary files from the web-server outside of its specified path.


    nihil
    Wotcher mate!

    I don't think there is such a thing as an "arbitrary file" I think the context is like this:

    arbitrary (file) deletion
    arbitrary (file) overwriting
    arbitrary (file) insertion

    And so on..............I guess that makes "arbitrary an adverb or whatever, that is, it qualifies the action (verb), and not the object (noun, i.e. "file"), in which case it would be an adjectival pronoun.

    Basically it means without negotiation/permission etc. For example, a lot of malware performs arbitrary actions on a system.

    So one could have an "arbitrary" action, but a "mandatory" file. In both cases you have no choice

    In TheSpecialist's example, he is "arbitrarily retrieving files"


    EDIT: And in my next class we will do the gerund and gerundive

    steve.milner
    To test if a file is an arbitary file hover the mouse over the filename and click the ANY key.
    If you fail to get a dialogue message then it an be assumed that that file is an aribtary file.

    Sorry, couldn't resist
    An arbitrary file really means, AFAIK, any file on the system. The reason for the word aribtrary is it usually means "outside the scope of the vulnerable application."

    So if i'm running a web site that has some vulnerability allowing access to modify the files that are a part of the web site, they're not "arbitrary" files. If I can access any file that may be on the box, those are arbitrary.

    Now that i've written all of that, those of you with more experience please tell me how correct it is.

    AO Senior Cow-beller
    zencoder
    Timmy, you've got the gist of it. s0nIc, I think you've misunderstood the semantics of the word as it was used. "This exploit allows arbitrary access to the system."

    Main Entry: ar·bi·trary
    Pronunciation: 'är-b&-"trer-E
    Function: adjective
    <<snip less helpful definitions>>
    3 b : existing or coming about seemingly at random or by chance or as a capricious and unreasonable act of will <when a task is not seen in a meaningful context it is experienced as being arbitrary -- Nehemiah Jordan>
