Mailing List Archive

Plugin 11359 UploadLite cgi: Show location of CGI in the report
Hi,

I've attached a patch to plugin 11359 (UploadLite cgi) to report where
upload.cgi was found. The new version also continues searching all of
the script directories for when the CGI is accessible in multiple locations.

The check for "PerlScriptsJavascript.com" in the HTTP response could
possibly be improved too, as other scripts may include this text. I
didn't change this because the plugin correctly detects Upload Lite, and
I haven't seen any false positives on other scripts. Here is an extract
from the CGI:

# Upload Lite.
# ?2002, PerlscriptsJavaScript.com
#
# Requirements: Perl5 WINDOWS NT or UNIX
# Created: Febuary , 2001
# Author: John Krinelos
#
# Version: 3.22

Regards
--
Simon Ward

Operations Security Specialist, Westpoint Ltd
Albion Wharf, 19 Albion Street, Manchester M1 5LN, United Kingdom

Web: www.westpoint.ltd.uk
Tel: +44-161-2371028
Re: Plugin 11359 UploadLite cgi: Show location of CGI in the report [ In reply to ]
On 05/01/07 10:50, Simon Ward wrote:

> I've attached a patch to plugin 11359 (UploadLite cgi) to report where
> upload.cgi was found.

Hi again. I've just committed changes with your improvements, although
additional directories are checked only if thorough tests are enabled.

> The check for "PerlScriptsJavascript.com" in the HTTP response could
> possibly be improved too,

The plugin now checks for some text as found in versions 3.22 and 4.0 of
the script.

George
--
theall@tenablesecurity.com
_______________________________________________
Plugins-writers mailing list
Plugins-writers@list.nessus.org
http://mail.nessus.org/mailman/listinfo/plugins-writers
Re: Plugin 11359 UploadLite cgi: Show location of CGI in the report [ In reply to ]
George A. Theall wrote:

> Hi again. I've just committed changes with your improvements, although
> additional directories are checked only if thorough tests are enabled.
> [...]
> The plugin now checks for some text as found in versions 3.22 and 4.0 of
> the script.

Tested and working. Thanks.
--
Simon Ward

Operations Security Specialist, Westpoint Ltd
Albion Wharf, 19 Albion Street, Manchester M1 5LN, United Kingdom

Web: www.westpoint.ltd.uk
Tel: +44-161-2371028
_______________________________________________
Plugins-writers mailing list
Plugins-writers@list.nessus.org
http://mail.nessus.org/mailman/listinfo/plugins-writers