[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Full-disclosure] Is OWASP vulnerable ??



--On March 10, 2007 11:37:25 PM -0500 Valdis.Kletnieks@xxxxxx wrote:

Yeah, a 404 page controlled by the server might just be too chatty and
give away info - but if you can control the input that creates the 404
page, it gets more interesting...

You can't be serious. I can "control" a server and "force" it to give me a 404 simply by typing in a page that doesn't exist. You know - like http://www.vt.edu/bogus.html

Paul Schmehl (pauls@xxxxxxxxxxxx)
Senior Information Security Analyst
The University of Texas at Dallas
http://www.utdallas.edu/ir/security/

Attachment: p7s4i78iSsX8C.p7s
Description: S/MIME cryptographic signature

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/