exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

htdig.txt

htdig.txt
Posted Mar 1, 2000
Authored by Geoff Hutchison

Htdig 3.1.4 search engine allows any file on the system to be read via CGI binary htsearch. Exploit information included.

tags | exploit, cgi
SHA-256 | 1eecacdd74cf1f2d6d72a6122781d4380abec3bf059830728e3f5f5d2e059c08

htdig.txt

Change Mirror Download
software:  ht://Dig
URL: https://www.htdig.org/
Version: 3.1.4, 3.2.0b1 and previous
Platforms: Unix, Win32, MacOS, Mac OS X Server
Type: CGI, Input validation problem
Vendor status: Notified, patch already available
Date: 02/28/2000

Summary:

Any remote user can view arbitrary files on your system with the
privileges of the web user.

Vulnerability:

The CGI does not properly verify form input. Many of the form
fields are applied as configuration attributes regardless of contents. The
configuration code allows config files to include other files through the
use of backticks, e.g.:

start_url: `/var/htdig/htdig.urls`

No distinction was made between CGI input and configuration file input
and both would be expanded for variables or file includes.

Exploit:

e.g. (this no longer works)
<https://www.htdig.org/cgi-bin/htsearch?exclude=%60/etc/passwd%60>

The file will show up in the source of the resulting page in the
"exclude" field of the search form. Other variations could be applied.

Workaround:

The recent 3.1.5 release fixes this problem. For the beta release
of 3.2.0b1, users should update to the latest development snapshot,
htdig-3.2.0b2-022700 and a 3.2.0b2 release will come out shortly. A patch
is also available to update from 3.1.4 to 3.1.5.

--
-Geoff Hutchison
Williams Students Online
https://wso.williams.edu/


Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    38 Files
  • 11
    Sep 11th
    21 Files
  • 12
    Sep 12th
    40 Files
  • 13
    Sep 13th
    18 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    21 Files
  • 17
    Sep 17th
    51 Files
  • 18
    Sep 18th
    23 Files
  • 19
    Sep 19th
    48 Files
  • 20
    Sep 20th
    36 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    38 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close