Return-Path: Delivered-To: apmail-new-httpd-archive@apache.org Received: (qmail 11470 invoked by uid 500); 13 Jun 2001 22:36:48 -0000 Mailing-List: contact new-httpd-help@apache.org; run by ezmlm Precedence: bulk Reply-To: new-httpd@apache.org list-help: list-unsubscribe: list-post: Delivered-To: mailing list new-httpd@apache.org Received: (qmail 11453 invoked from network); 13 Jun 2001 22:36:46 -0000 Message-ID: <3B27EAF9.5E89BCA0@weirdness.com> Date: Wed, 13 Jun 2001 16:36:41 -0600 From: Jerry Baker X-Mailer: Mozilla 4.77 [en] (Windows NT 5.0; U) X-Accept-Language: en MIME-Version: 1.0 To: new-httpd@apache.org Subject: Re: (DUH) Bugtraq ID 2503 : Apache Artificially Long Slash Path DirectoryListing Exploit (fwd) References: <3B27E782.FFA6F57D@weirdness.com> Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit X-Spam-Rating: h31.sny.collab.net 1.6.2 0/1000/N Jerry Baker wrote: > > I tried it with up to 300 "/"'s on Win2k without success. > > -- > Jerry Baker Would help if I had read that it took 4000+. Heh. Still no success on Win2k Advanced Server up to 5000. -- Jerry Baker "The only normal people are the ones you don't know very well." - Joe Ancis PGP Key: http://keyserver.pgp.com:80/pks/lookup?op=get&exact=off&search=0xD4B2493F LAME Binaries: http://jerbaker.dhs.org/lame