Vulnerability Development mailing list archives

RE: Apache HTTPD's magical behavior


From: "Golden_Eternity" <bhodi_jabir () yahoo com>
Date: Fri, 30 Nov 2001 12:05:16 -0800

Today I was browsing the Internet when I came across a server that would
not let me view the contents of the root dir.

However, it did let me view the contents of a dir within it's
root dir. So
I tried the following:

http://<server>/<dir i can browse>../

And for some reason it allowed me to view the root dir and all of
its contents.

Do we know if this works if Indexes is turned off? Or does this just bypass
the DirectoryIndex tag?

BTW, I have tested this on 1.3.17 and it doesn't seem to be affected.



Current thread: