On Wed, Sep 29, 2010 at 1:59 PM, David Connors <[email protected]> wrote: >> The main problem is having effectively web-accessible content in the >> web root. It's virtually a flat-out "don't ever do it". > > I agree. But there have been parent path escaping issues in the past > that allow attackers to reference files outside of the web root even. > > A bit more clarity around this part of the exploit would be more helpful.
Agreed. It's definitely using that file to do the code execution though. But I'm struggling to find any information on exactly what happens when you hit WebResource.axd (i.e. what code path do you end up? I can't find it, if anyone knows please let me know ...) -- silky http://dnoondt.wordpress.com/ "Every morning when I wake up, I experience an exquisite joy — the joy of being this signature."
