exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

asp.runtime-error.txt

asp.runtime-error.txt
Posted Feb 11, 2000
Authored by Jerry Walsh | Site jwsg.com

Active server pages (ASP) with runtime errors expose a security hole that publishes the full source code name to the caller. If these scripts are published on the internet before they are debugged by the programmer, the major search engines index them. These indexed ASP pages can be then located with a simple search. The search results publish the full path and file name for the ASP scripts. This URL can be viewed in a browser and may reveal full source code with details of business logic, database location and structure.

tags | exploit, asp
SHA-256 | 8df08f77a97c4061a43c01be319e5ef4511a09240fd42e5c021cd65c36a798af

asp.runtime-error.txt

Change Mirror Download
Forwarded with permission of the author. Please direct all replies to
jwalsh@jwsg.com.

Ben Greenbaum
Director of Site Content
Security Focus
http://www.securityfocus.com

---------- Forwarded message ----------
Description:
============
Active server pages (ASP) with runtime errors
expose a security hole that publishes
the full source code name to the caller.
If these scripts are published on the
internet before they are debugged by
the programmer, the major search
engines index them. These indexed
ASP pages can be then located with a
simple search. The search results publish
the full path and file name for the ASP
scripts. This URL can be viewed in a browser
and may reveal full source code with
details of business logic, database location
and structure.

Procedure:
==========
- In the Altavisa search engine execute a search for
+"Microsoft VBScript runtime error" +".inc, "

- Look for search results that include the full
path and filename for an include (.inc) file.

- Append the include filename to the host name
and call this up in a web browser.
Example: www.rodney.com/stationery/browser.inc

Examples:
=========
http://shopping.altavista.com/inc/lib/prep.lib
Exposes database connections and properties, resource locations,
cookie logic, server IP addresses, business logic

http://www.justshop.com/SFLib/ship.inc
Exposes database properties, business logic

http://www.bbclub.com:8013/includes/general.inc
Exposes cobranding business logic

http://www.salest.com/corporate/admin/include/jobs.inc
Exposes datafile locations and structure

http://www.bjsbabes.com/SFLib/design.inc
Exposes source code for StoreFront 2000 including
database structure

http://www.ffg.com/scripts/IsSearchEngine.inc
Exposes search engine log

http://www.wcastl.com/include/functions.inc
Exposes members email addresses and
private comments file http://www.wcastl.com/flat/comments.txt

http://www.traveler.net/two/cookies.inc
Exposes cookie logic

Resolution:
===========

- Search engines should not index pages that
have ASP runtime errors.

- Programmers should fully debug their ASP
scripts before publishing them on the web

- Security administrators need to secure
the ASP include files so that external users
can not view them.




===========================
Jerry Walsh
JW's Software Gems
Email jwalsh@jwsg.com
Phone (949) 855-0233
Website http://www.jwsg.com
===========================


Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close