|
|
|
|
Menu |
|
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
|
User Info |
|
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 51
Members: 0
Total: 51
|
|
|
|
|
|
Full disclosure |
|
|
|
|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
WTF is "Return Flushing" or "RE eploit" |
|
Posted: Sat Jun 03, 2006 6:02 pm |
|
|
waraxe |
Site admin |
|
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
|
|
|
|
So i stumbled to this info page @ wikipedia:
http://en.wikipedia.org/wiki/Directory_traversal
Code: |
Current Method Also Known As (Return Flushing, RE Exploit) Due to most vulnerabilities being recently patched as such sites as http://milw0rm.com have been released publically, most attackers have been forced to develop exploits of their own. One such method is return flushing, or re'ing. This attempt consist of a parallel paradox. On the attackers computer, the request points to a file that does exist in the directory specified. Usually the attacker specially configures his or her own directories so they are unique and are rarely affiliated with the server's directories. The file usually included in the get request is cmd.exe, or other shell applications. The failed get request results in a resolvement, bypassing the typical 404 error and/or 403 error pages, and resolves the request to the base of the domain/server, revealing all the content resideing within the domain/server. No matter what utility/environment is being utilized the domain/server. This accounts for several environments such as Apache.
|
Can someone explain me details, so I can understand? |
|
|
|
|
|
|
|
|
Posted: Sun Jun 04, 2006 8:56 am |
|
|
y3dips |
Valuable expert |
|
|
Joined: Feb 25, 2005 |
Posts: 281 |
Location: Indonesia |
|
|
|
|
|
|
dont know who wroet that..
i think in wiki u can edited it...
same like you, could anyone tell me about Return Flushing, RE Exploit ..
|
|
_________________ IO::y3dips->new(http://clog.ammar.web.id); |
|
|
|
Posted: Fri Jun 16, 2006 7:58 am |
|
|
shai-tan |
Valuable expert |
|
|
Joined: Feb 22, 2005 |
Posts: 477 |
|
|
|
|
|
|
|
lol You should have seen the Wikipedia entry for Hurd and Ututo.... Fixed now thankfully. |
|
_________________ Shai-tan
?In short: just say NO TO DRUGS, and maybe you won?t end up like the Hurd people.? -- Linus Torvalds |
|
|
|
www.waraxe.us Forum Index -> All other security holes
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|
|