Hacked by a .gif - Posted (1766 Views)
Average Member
Panhandler
Posts: 783
783
I have a asp operated photo gallery that permitted .gif files to be uploaded (that's been changed!)
A hacker uploaded and used a file named zor.asp;.gif to get in.
Here's a text copy for anyone interested: link Original file was named: zor.asp;.gif

 Sort direction, for dates DESC means newest first  
 Page size 
Posted
Snitz Forums Admin
ruirib
Posts: 26364
26364
I did that, there is a forum I help with that uses some sort of photo gallery vulnerable to this as well, and removing the semicolon meant that the file was no longer executed. I did it with an asp file, sothe code was displayed instead, as if it was a text file.
Posted
Support Moderator
Doug G
Posts: 6493
6493
For some reading enjoyment: http://blogs.iis.net/nazim/archive/2009/12/29/public-disclosure-of-iis-security-issue-with-semi-colons-in-url.aspx
======
Doug G
======
Computer history and help at www.dougscode.com
Posted
Snitz Forums Admin
ruirib
Posts: 26364
26364
You Must enter a message