Michel Arboi wrote:
> > But note that Roxen success is based on
> > "Directory listing of" and Weblogic is "directory listing of",
>
> ... which both fail if the system locale has been set to something
> other than English :-\
People use other languages? WHAT? :)
> IMHO, we should:
> GET /
> GET /%00/
> If both answer 200 and the result is different, the server is
> vulnerable. No?
What about active pages? Someone puts the current time (with seconds) on
a page & they will be different every time requested (assuming the
server sends / instead of /%00/). But yes, non-English language
settings is a problem--probably in TONS of plugins.
-Sullo
___________________________________________________
http://www.cirt.net/ Home of Nikto