- Detect Directory Traversal Vulnerabilities on HTTP / FTP Servers - DotDotPwn

THE AUTHOR IS NOT RESPONSIBLE BY ANY DAMAGE THAT THIS SOFTWARE MAY CAUSE, THIS TOOL WAS DEVELOPED FOR SECURITY RESEARCH PURPOSES, USE THIS BY YOUR OWN RISK. IF YOU DO NOT AGREE WITH THIS STATEMENT, PLEASE DO NOT USE THE TOOL.

Sometimes, developer's  just create some "generic" filters in order to prevent security issues, like the ones related to web technolgies such as XSS, SQLi or Directory traversals, but not all the times they take care about the obscure strings that an attacker can use to bypass many those weakest filters. With the use of DotDotPwn tool, we can confirm if a Directory traversal attack can be performed -even- if an HTTP/FTP server has already implemented any kind of filter against this attack and knowing *ALL* the available attack strings, developers can strength their web application/client-server filters.

DotDotPwn is a simple PERL tool which detects several Directory Traversal Vulnerabilities on HTTP/FTP Servers. This AttackDB version currently has 871 traversal payloads.

DotDotPwn Features:
 * Detects Directory traversal vulnerabilities on remote HTTP/FTP server systems.
 * DotDotPwn checks the presence of boot.ini on the vulnerable systems through Directory traversal vulnerabilities, so it is assumed that the tested systems are Windows based HTTP/FTP servers.
 * Currently, the traversal database holds 871 attack payloads. Use the -update flag to perform an online fresh update.

DotDotPwn requirements:
* Perl with support of HTTP::Lite and Net::FTP modules (these can be easily downloaded from the CPAN site - http://search.cpan.org/)

Using DotDotPwn:
Untar the package using command: tar -zxvf ddpwn.tar.gz
type the following command to run the directory traversal vulnerabilities test against web server:
perl ddpwn.pl -hhtp 192.168.1.2


Read more about DotDotPwn - here


source:http://linuxpoison.blogspot.com/2010/10/135781677518024.html

Labels

Web Search Gmail Google Docs Mobile YouTube Google Maps Google Chrome User interface Tips iGoogle Social Google Reader Traffic Making Devices cpp programming Ads Image Search Google Calendar tips dan trik Google Video Google Translate web programming Picasa Web Albums Blogger Google News Google Earth Yahoo Android Google Talk Google Plus Greasemonkey Security software download info Firefox extensions Google Toolbar Software OneBox Google Apps Google Suggest SEO Traffic tips Book Search API Acquisitions InOut Visualization Web Design Method for Getting Ultimate Traffic Webmasters Google Desktop How to Blogging Music Nostalgia orkut Google Chrome OS Google Contacts Google Notebook SQL programming Google Local Make Money Windows Live GDrive Google Gears April Fools Day Google Analytics Google Co-op visual basic Knowledge java programming Google Checkout Google Instant Google Bookmarks Google Phone Google Trends Web History mp3 download Easter Egg Google Profiles Blog Search Google Buzz Google Services Site Map for Ur Site game download games trick Google Pack Spam cerita hidup Picasa Product's Marketing Universal Search FeedBurner Google Groups Month in review Twitter Traffic AJAX Search Google Dictionary Google Sites Google Update Page Creator Game Google Finance Google Goggles Google Music file download Annoyances Froogle Google Base Google Latitude Google Voice Google Wave Google Health Google Scholar PlusBox SearchMash teknologi unik video download windows Facebook Traffic Social Media Marketing Yahoo Pipes Google Play Google Promos Google TV SketchUp WEB Domain WWW World Wide Service chord Improve Adsence Earning jurnalistik sistem operasi AdWords Traffic App Designing Tips and Tricks WEB Hosting linux How to Get Hosting Linux Kernel WEB Errors Writing Content award business communication ubuntu unik