_
| The Translate:f Security Hole
|
|
| Recently a Windows 2000 / IIS 5 security hole was discovered that allows the source of ASP pages to be viewed through a simple HTTP request. This special HTTP request simply needs to be directed to an ASP page that is hosted on a Windows 2000 box that does not have either the security hole patch or Service Pack 1 installed. What makes this HTTP request special is that the ASP page being requested ends with a backslash and the HTTP header Translate: f is sent along. You can see ASP code that sends such a request at: |
| Version: [N/A] Cost: [N/A] | Platforms:
[N/A] |
| Visit Home Page | Modify This Resource
| Report a Problem With Link |
| Visitor
Comments: |
| There are currently no comments available. |
|
|
|