PEAK XOOPS - Re: New Protector is testing now in englishin japanese

Re: New Protector is testing now

Target News
Subject New Protector is testing now
Summary XoopsProtector 2.2 will be released soon.I'm now testing the module in this site.The features of the next version...- welcomed major search engines.- protect against bad-mannered crawlers- PHP5 friendly (perhaps...)- rescue modeand so on...

List posts in the topic

normal Re: New Protector is testing now

msg# 1.1.1.1.1.1.1
depth:
6
Previous post - Next post | Parent - Children.1 | Posted on 2004/12/20 6:40 | Last modified
GIJOE  ÀèǤ·³Áâ   Posts: 4110
hi Yuji.

If a wrapping module which accepts filename via GET exists, there is a possiblity that a vulnerablity exits like this:

http://(your site)/modules/badmodule/?page=../../mainfile.php

This can display the content of manfile.php
(Of course, this is just a sample.)

So, protector inhibits '../' patterns which looks like file specifications.
Votes:0 Average:0.00

Posts tree

  Advanced search


Login
Username or e-mail:

Password:

Remember Me

Lost Password?

Register now!