xatar
04-04-2007, 10:35 AM
Hi all.
I am doing a pentest and have found a vulnerability with a web application that allows the arbitrary reading of files that are readable by the web server account.
I can get the /etc/passwd, /etc/snmp/snmp.conf/, /etc/hosts etc. I cannot get the /etc/shadow file as it is only readable by root.
Are there any files in particular on RedHat Enterprise Linux (2.6.9-34 EL) that I should look for? Remember that they need to be globally readable by the web server! r--r--r--
Thanks,
xatar.
I am doing a pentest and have found a vulnerability with a web application that allows the arbitrary reading of files that are readable by the web server account.
I can get the /etc/passwd, /etc/snmp/snmp.conf/, /etc/hosts etc. I cannot get the /etc/shadow file as it is only readable by root.
Are there any files in particular on RedHat Enterprise Linux (2.6.9-34 EL) that I should look for? Remember that they need to be globally readable by the web server! r--r--r--
Thanks,
xatar.